Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aviatrix

First CVE: Dec 5, 2019Active for: 7 yearsTotal CVEs: 21
77.3
VTI Score
TOP TARGET

Aviatrix develops cloud networking and secure access platforms, with its vulnerability footprint concentrated in the Controller, Gateway, and VPN Client products that form the core of multicloud connectivity infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability. The exposure recurs through weakness classes including cross-site request forgery, incorrect permission assignment for critical resources, cleartext storage of sensitive information, and accessible configuration files—patterns characteristic of web-facing control planes and credential-handling challenges in cloud-orchestration software. Defenders should prioritize patching of internet-reachable Controller instances and review stored credential handling; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked vendors
9.5%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Aviatrix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2019
6 years ago
Most Recent CVE
Jan 8, 2025
562 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-50603CRITICAL
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthent
Jan 8, 20259.898YESYES
CVE-2021-40870CRITICAL
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to ex
Sep 13, 20219.897YESYES
CVE-2020-26553CRITICAL
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.
Nov 17, 20209.829NONO
CVE-2020-13412HIGH
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.
May 22, 20208.828NONO
CVE-2022-38368HIGH
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject
Aug 15, 20228.827NONO
CVE-2020-26548HIGH
An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.
Nov 17, 20208.826NONO
CVE-2020-13415HIGH
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML asse
May 22, 20207.525NONO
CVE-2020-13414HIGH
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
May 22, 20207.525NONO
CVE-2019-17387HIGH
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Lin
Dec 5, 20197.825NONO
CVE-2021-31776HIGH
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unpri
Apr 29, 20217.824NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
10%
67%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (14.3%)
Network18 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (90.5%)
Unknown0 (0.0%)
Required2 (9.5%)
Privileges Required
Low5 (23.8%)
High0 (0.0%)
None16 (76.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
2 CVEs
9.5% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aviatrix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aviatrix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aviatrix's Products

View all 1 CNAs →

Top CWEs