CVE-2022-38368
15.08.2022, 22:15
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.Enginsight
Vendor | Product | Version |
---|---|---|
aviatrix | gateway | 𝑥 < 6.6.5712 |
aviatrix | gateway | 6.7.0 ≤ 𝑥 < 6.7.1376 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration