CVE-2019-17387 is an authentication flaw in the AVPNC_RP service of Aviatrix VPN Client versions through 2.2.10, impacting Windows, Linux, and macOS platforms. This vulnerability carries a CVSS score of 7.8 (High), indicating that a local, low-privileged attacker can achieve arbitrary code execution and gain elevated privileges with low attack complexity. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.2.10CPE matchmatch criteria | cpe:2.3:a:aviatrix:vpn_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.