Vulnerability Details CVE-2019-17388
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2019-17388
-
cpe:2.3:a:aviatrix:vpn_client:-
-
cpe:2.3:a:aviatrix:vpn_client:1.0
-
cpe:2.3:a:aviatrix:vpn_client:1.1
-
cpe:2.3:a:aviatrix:vpn_client:1.10.6
-
cpe:2.3:a:aviatrix:vpn_client:1.2
-
cpe:2.3:a:aviatrix:vpn_client:1.3
-
cpe:2.3:a:aviatrix:vpn_client:1.4
-
cpe:2.3:a:aviatrix:vpn_client:1.5
-
cpe:2.3:a:aviatrix:vpn_client:1.6
-
cpe:2.3:a:aviatrix:vpn_client:1.7
-
cpe:2.3:a:aviatrix:vpn_client:1.8
-
cpe:2.3:a:aviatrix:vpn_client:1.9
-
cpe:2.3:a:aviatrix:vpn_client:2.0.3
-
cpe:2.3:a:aviatrix:vpn_client:2.1.3
-
cpe:2.3:a:aviatrix:vpn_client:2.2.10
-
cpe:2.3:o:freebsd:freebsd:-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-