Vulnerability Details CVE-2020-13415
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-13415
-
cpe:2.3:a:aviatrix:controller:2.5
-
cpe:2.3:a:aviatrix:controller:2.6
-
cpe:2.3:a:aviatrix:controller:2.7
-
cpe:2.3:a:aviatrix:controller:3.0
-
cpe:2.3:a:aviatrix:controller:3.1
-
cpe:2.3:a:aviatrix:controller:3.2
-
cpe:2.3:a:aviatrix:controller:3.3
-
cpe:2.3:a:aviatrix:controller:3.4
-
cpe:2.3:a:aviatrix:controller:3.5
-
cpe:2.3:a:aviatrix:controller:4.0
-
cpe:2.3:a:aviatrix:controller:4.1.914
-
cpe:2.3:a:aviatrix:controller:4.1.946
-
cpe:2.3:a:aviatrix:controller:4.2.634
-
cpe:2.3:a:aviatrix:controller:4.2.740
-
cpe:2.3:a:aviatrix:controller:4.2.764
-
cpe:2.3:a:aviatrix:controller:4.3.1230
-
cpe:2.3:a:aviatrix:controller:4.3.1262
-
cpe:2.3:a:aviatrix:controller:4.3.1275
-
cpe:2.3:a:aviatrix:controller:4.6.587
-
cpe:2.3:a:aviatrix:controller:4.7.378
-
cpe:2.3:a:aviatrix:controller:4.7.419
-
cpe:2.3:a:aviatrix:controller:4.7.473
-
cpe:2.3:a:aviatrix:controller:4.7.494
-
cpe:2.3:a:aviatrix:controller:4.7.501
-
cpe:2.3:a:aviatrix:controller:4.7.581
-
cpe:2.3:a:aviatrix:controller:4.7.590
-
cpe:2.3:a:aviatrix:controller:5.0.2667
-
cpe:2.3:a:aviatrix:controller:5.0.2754
-
cpe:2.3:a:aviatrix:controller:5.0.2768
-
cpe:2.3:a:aviatrix:controller:5.0.2773
-
cpe:2.3:a:aviatrix:controller:5.0.2782