Vulnerability Details CVE-2022-38368
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-38368
-
cpe:2.3:a:aviatrix:gateway:-
-
cpe:2.3:a:aviatrix:gateway:2.5
-
cpe:2.3:a:aviatrix:gateway:2.6
-
cpe:2.3:a:aviatrix:gateway:2.7
-
cpe:2.3:a:aviatrix:gateway:3.0
-
cpe:2.3:a:aviatrix:gateway:3.1
-
cpe:2.3:a:aviatrix:gateway:3.2
-
cpe:2.3:a:aviatrix:gateway:3.3
-
cpe:2.3:a:aviatrix:gateway:3.4
-
cpe:2.3:a:aviatrix:gateway:3.5
-
cpe:2.3:a:aviatrix:gateway:4.0
-
cpe:2.3:a:aviatrix:gateway:5.0.2667
-
cpe:2.3:a:aviatrix:gateway:5.3
-
cpe:2.3:a:aviatrix:gateway:5.4.1204
-
cpe:2.3:a:aviatrix:gateway:6.3.2092
-
cpe:2.3:a:aviatrix:gateway:6.3.2548
-
cpe:2.3:a:aviatrix:gateway:6.3.2551
-
cpe:2.3:a:aviatrix:gateway:6.4.2783
-
cpe:2.3:a:aviatrix:gateway:6.4.2791
-
cpe:2.3:a:aviatrix:gateway:6.4.2830
-
cpe:2.3:a:aviatrix:gateway:6.4.2859
-
cpe:2.3:a:aviatrix:gateway:6.4.2945
-
cpe:2.3:a:aviatrix:gateway:6.4.2973
-
cpe:2.3:a:aviatrix:gateway:6.4.2995
-
cpe:2.3:a:aviatrix:gateway:6.4.3008
-
cpe:2.3:a:aviatrix:gateway:6.4.3015
-
cpe:2.3:a:aviatrix:gateway:6.4.3049
-
cpe:2.3:a:aviatrix:gateway:6.4.3057
-
cpe:2.3:a:aviatrix:gateway:6.5.1905
-
cpe:2.3:a:aviatrix:gateway:6.5.1922
-
cpe:2.3:a:aviatrix:gateway:6.5.2608
-
cpe:2.3:a:aviatrix:gateway:6.5.2613
-
cpe:2.3:a:aviatrix:gateway:6.5.2721
-
cpe:2.3:a:aviatrix:gateway:6.5.2835
-
cpe:2.3:a:aviatrix:gateway:6.5.2898
-
cpe:2.3:a:aviatrix:gateway:6.5.3006
-
cpe:2.3:a:aviatrix:gateway:6.5.3012
-
cpe:2.3:a:aviatrix:gateway:6.5.3166
-
cpe:2.3:a:aviatrix:gateway:6.5.3233
-
cpe:2.3:a:aviatrix:gateway:6.6.5224
-
cpe:2.3:a:aviatrix:gateway:6.6.5230
-
cpe:2.3:a:aviatrix:gateway:6.6.5404
-
cpe:2.3:a:aviatrix:gateway:6.6.5409
-
cpe:2.3:a:aviatrix:gateway:6.6.5413
-
cpe:2.3:a:aviatrix:gateway:6.6.5545
-
cpe:2.3:a:aviatrix:gateway:6.6.5612
-
cpe:2.3:a:aviatrix:gateway:6.6.5662
-
cpe:2.3:a:aviatrix:gateway:6.6.5667
-
cpe:2.3:a:aviatrix:gateway:6.7.0
-
cpe:2.3:a:aviatrix:gateway:6.7.1185
-
cpe:2.3:a:aviatrix:gateway:6.7.1186
-
cpe:2.3:a:aviatrix:gateway:6.7.1319
-
cpe:2.3:a:aviatrix:gateway:6.7.1324
-
cpe:2.3:a:aviatrix:gateway:6.7.1325