Vulnerability Details CVE-2020-27569
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-27569
-
cpe:2.3:a:aviatrix:openvpn:-
-
cpe:2.3:a:aviatrix:openvpn:1.0
-
cpe:2.3:a:aviatrix:openvpn:1.1
-
cpe:2.3:a:aviatrix:openvpn:1.10.16
-
cpe:2.3:a:aviatrix:openvpn:1.2
-
cpe:2.3:a:aviatrix:openvpn:1.3
-
cpe:2.3:a:aviatrix:openvpn:1.4
-
cpe:2.3:a:aviatrix:openvpn:1.5
-
cpe:2.3:a:aviatrix:openvpn:1.6
-
cpe:2.3:a:aviatrix:openvpn:1.7
-
cpe:2.3:a:aviatrix:openvpn:1.8
-
cpe:2.3:a:aviatrix:openvpn:1.9
-
cpe:2.3:a:aviatrix:openvpn:2.0.3
-
cpe:2.3:a:aviatrix:openvpn:2.1.3
-
cpe:2.3:a:aviatrix:openvpn:2.2.10
-
cpe:2.3:a:aviatrix:openvpn:2.3.10
-
cpe:2.3:a:aviatrix:openvpn:2.4.10
-
cpe:2.3:a:aviatrix:openvpn:2.5.7
-
cpe:2.3:a:aviatrix:openvpn:2.6.6
-
cpe:2.3:a:aviatrix:openvpn:2.7.9
-
cpe:2.3:a:aviatrix:openvpn:2.8.2