QID 731354

Date Published: 2024-04-08

QID 731354: Aviatrix Controller Remote Code Execution (RCE) Vulnerability (Intrusive Check)

Aviatrix Controller is a cloud network management platform that can simplify networking tasks on public clouds.

Aviatrix Controller 6.x before 6.5-1804.1922 contains a vulnerability that allows unrestricted upload of php files, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Affected Versions:
Aviatrix Controller 6.x before 6.5-1804.1922

QID Detection Logic (Unauthenticated):
This is an intrusive check. This detection creates a file 'qualystest731354.php'. This file contains static content, i.e. the md5 hash of qualystest731354.

Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Aviatrix Controller version 6.5-1804.1922 or later to mitigate this vulnerability. For more information please refer to the Aviatrix Security Advisory

    Vendor References

    CVEs related to QID 731354

    Software Advisories
    Advisory ID Software Component Link
    Aviatrix Security Advisory URL Logo docs.aviatrix.com/HowTos/UCC_Release_Notes.html#security-note-9-11-2021