CVE-2020-26553

CRITICAL

Aviatrix Controller <R6.0.2483 - Code Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0084
EPSS Percentile 74.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
aviatrix/controller 5.3.1516
Published Nov 17, 2020
Tracked Since Feb 18, 2026