CVE Vulnerabilities

CVE-2022-38368

Improper Authentication

Published: Aug 15, 2022 | Modified: Aug 16, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gateway Aviatrix * 6.6.5712 (excluding)
Gateway Aviatrix 6.7.0 (including) 6.7.1376 (excluding)

Potential Mitigations

References