Controller Aviatrix Controller

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Aviatrix Controller.

By the Year

In 2026 there have been 0 vulnerabilities in Aviatrix Controller. Last year, in 2025 Controller had 2 security vulnerabilities published. Right now, Controller is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 2 10.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 8.65
2020 8 7.68

It may take a day or so for new Controller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aviatrix Controller Security Vulnerabilities

Aviatrix Controller <7.1.4208,7.2.5090,8.0.0 - No Rate Limiting on Reset PIN(BF)
CVE-2025-2171 - June 23, 2025

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN

Aviatrix Controller <=7.1.4191 Cmd Inject via /v1/api (CVE-2024-50603)
CVE-2024-50603 10 - Critical - January 08, 2025

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Shell injection

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922
CVE-2021-40870 9.8 - Critical - September 13, 2021

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Insecure File Permissions exist in Aviatrix Controller 5.3.1516
CVE-2020-27568 7.5 - High - April 21, 2021

Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.

Incorrect Permission Assignment for Critical Resource

An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26548 8.8 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26549 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

Files or Directories Accessible to External Parties

An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26550 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.

Insufficiently Protected Credentials

An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26551 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

Cleartext Storage of Sensitive Information

An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26552 7.5 - High - November 17, 2020

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

Inadequate Encryption Strength

An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26553 9.8 - Critical - November 17, 2020

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

Unrestricted File Upload

An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13414 7.5 - High - May 22, 2020

An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.

Use of Hard-coded Credentials

An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13413 5.3 - Medium - May 22, 2020

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.

Side Channel Attack

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Aviatrix Controller or by Aviatrix? Click the Watch button to subscribe.

Aviatrix
Vendor

subscribe