Aviatrix Controller
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Aviatrix Controller.
By the Year
In 2026 there have been 0 vulnerabilities in Aviatrix Controller. Last year, in 2025 Controller had 2 security vulnerabilities published. Right now, Controller is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 10.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 2 | 8.65 |
| 2020 | 8 | 7.68 |
It may take a day or so for new Controller vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aviatrix Controller Security Vulnerabilities
Aviatrix Controller <7.1.4208,7.2.5090,8.0.0 - No Rate Limiting on Reset PIN(BF)
CVE-2025-2171
- June 23, 2025
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
Aviatrix Controller <=7.1.4191 Cmd Inject via /v1/api (CVE-2024-50603)
CVE-2024-50603
10 - Critical
- January 08, 2025
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.
Shell injection
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922
CVE-2021-40870
9.8 - Critical
- September 13, 2021
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
Insecure File Permissions exist in Aviatrix Controller 5.3.1516
CVE-2020-27568
7.5 - High
- April 21, 2021
Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.
Incorrect Permission Assignment for Critical Resource
An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26548
8.8 - High
- November 17, 2020
An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.
An issue was discovered in Aviatrix Controller before R5.4.1290
CVE-2020-26549
7.5 - High
- November 17, 2020
An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.
Files or Directories Accessible to External Parties
An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26550
7.5 - High
- November 17, 2020
An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.
Insufficiently Protected Credentials
An issue was discovered in Aviatrix Controller before R5.3.1151
CVE-2020-26551
7.5 - High
- November 17, 2020
An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.
Cleartext Storage of Sensitive Information
An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26552
7.5 - High
- November 17, 2020
An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.
Inadequate Encryption Strength
An issue was discovered in Aviatrix Controller before R6.0.2483
CVE-2020-26553
9.8 - Critical
- November 17, 2020
An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.
Unrestricted File Upload
An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13414
7.5 - High
- May 22, 2020
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
Use of Hard-coded Credentials
An issue was discovered in Aviatrix Controller before 5.4.1204
CVE-2020-13413
5.3 - Medium
- May 22, 2020
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
Side Channel Attack
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Aviatrix Controller or by Aviatrix? Click the Watch button to subscribe.