An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
2021-09-13T08:15:13.913
2025-04-03T19:15:43.560
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | aviatrix | controller | < 6.2.2043 | Yes |
Application | aviatrix | controller | < 6.3.2490 | Yes |
Application | aviatrix | controller | < 6.4.2838 | Yes |
Application | aviatrix | controller | < 6.5.1922 | Yes |