Aviatrix develops cloud networking and secure access platforms, with its vulnerability footprint concentrated in the Controller, Gateway, and VPN Client products that form the core of multicloud connectivity infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability. The exposure recurs through weakness classes including cross-site request forgery, incorrect permission assignment for critical resources, cleartext storage of sensitive information, and accessible configuration files—patterns characteristic of web-facing control planes and credential-handling challenges in cloud-orchestration software. Defenders should prioritize patching of internet-reachable Controller instances and review stored credential handling; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aviatrix over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50603CRITICAL An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthent | Jan 8, 2025 | 9.8 | 98 | YES | YES |
CVE-2021-40870CRITICAL An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to ex | Sep 13, 2021 | 9.8 | 97 | YES | YES |
CVE-2020-26553CRITICAL An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree. | Nov 17, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-13412HIGH An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF. | May 22, 2020 | 8.8 | 28 | NO | NO |
CVE-2022-38368HIGH An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject | Aug 15, 2022 | 8.8 | 27 | NO | NO |
CVE-2020-26548HIGH An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system. | Nov 17, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-13415HIGH An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML asse | May 22, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-13414HIGH An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. | May 22, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-17387HIGH An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Lin | Dec 5, 2019 | 7.8 | 25 | NO | NO |
CVE-2021-31776HIGH Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unpri | Apr 29, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aviatrix.
Media articles that mention a CVE ID that affects a product developed by Aviatrix — matched by CVE ID, not by vendor name.