Vulnerability Details CVE-2022-38368
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.2%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-38368
-
cpe:2.3:a:aviatrix:gateway:-
-
cpe:2.3:a:aviatrix:gateway:2.5
-
cpe:2.3:a:aviatrix:gateway:2.6
-
cpe:2.3:a:aviatrix:gateway:2.7
-
cpe:2.3:a:aviatrix:gateway:3.0
-
cpe:2.3:a:aviatrix:gateway:3.1
-
cpe:2.3:a:aviatrix:gateway:3.2
-
cpe:2.3:a:aviatrix:gateway:3.3
-
cpe:2.3:a:aviatrix:gateway:3.4
-
cpe:2.3:a:aviatrix:gateway:3.5
-
cpe:2.3:a:aviatrix:gateway:4.0
-
cpe:2.3:a:aviatrix:gateway:5.0.2667
-
cpe:2.3:a:aviatrix:gateway:5.3
-
cpe:2.3:a:aviatrix:gateway:5.4.1204
-
cpe:2.3:a:aviatrix:gateway:6.3.2092
-
cpe:2.3:a:aviatrix:gateway:6.3.2548
-
cpe:2.3:a:aviatrix:gateway:6.3.2551
-
cpe:2.3:a:aviatrix:gateway:6.4.2783
-
cpe:2.3:a:aviatrix:gateway:6.4.2791
-
cpe:2.3:a:aviatrix:gateway:6.4.2830
-
cpe:2.3:a:aviatrix:gateway:6.4.2859
-
cpe:2.3:a:aviatrix:gateway:6.4.2945
-
cpe:2.3:a:aviatrix:gateway:6.4.2973
-
cpe:2.3:a:aviatrix:gateway:6.4.2995
-
cpe:2.3:a:aviatrix:gateway:6.4.3008
-
cpe:2.3:a:aviatrix:gateway:6.4.3015
-
cpe:2.3:a:aviatrix:gateway:6.4.3049
-
cpe:2.3:a:aviatrix:gateway:6.4.3057
-
cpe:2.3:a:aviatrix:gateway:6.5.1905
-
cpe:2.3:a:aviatrix:gateway:6.5.1922
-
cpe:2.3:a:aviatrix:gateway:6.5.2608
-
cpe:2.3:a:aviatrix:gateway:6.5.2613
-
cpe:2.3:a:aviatrix:gateway:6.5.2721
-
cpe:2.3:a:aviatrix:gateway:6.5.2835
-
cpe:2.3:a:aviatrix:gateway:6.5.2898
-
cpe:2.3:a:aviatrix:gateway:6.5.3006
-
cpe:2.3:a:aviatrix:gateway:6.5.3012
-
cpe:2.3:a:aviatrix:gateway:6.5.3166
-
cpe:2.3:a:aviatrix:gateway:6.5.3233
-
cpe:2.3:a:aviatrix:gateway:6.6.5224
-
cpe:2.3:a:aviatrix:gateway:6.6.5230
-
cpe:2.3:a:aviatrix:gateway:6.6.5404
-
cpe:2.3:a:aviatrix:gateway:6.6.5409
-
cpe:2.3:a:aviatrix:gateway:6.6.5413
-
cpe:2.3:a:aviatrix:gateway:6.6.5545
-
cpe:2.3:a:aviatrix:gateway:6.6.5612
-
cpe:2.3:a:aviatrix:gateway:6.6.5662
-
cpe:2.3:a:aviatrix:gateway:6.6.5667
-
cpe:2.3:a:aviatrix:gateway:6.7.0
-
cpe:2.3:a:aviatrix:gateway:6.7.1185
-
cpe:2.3:a:aviatrix:gateway:6.7.1186
-
cpe:2.3:a:aviatrix:gateway:6.7.1319
-
cpe:2.3:a:aviatrix:gateway:6.7.1324
-
cpe:2.3:a:aviatrix:gateway:6.7.1325