CVE-2020-13417
NixOS vulnerability analysis and mitigation

Overview

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before version 2.10.7, which was identified as an incomplete fix for CVE-2020-7224. The vulnerability affects Linux, macOS, and Windows installations specifically related to certain OpenSSL parameters. The issue was disclosed on May 22, 2020, and received a CVSS score of 7.5, indicating high severity (CISA Bulletin).

Technical details

The vulnerability exists in the VPN service where dangerous OpenSSL parameters could lead to unauthorized code execution. This was a follow-up to a previous vulnerability (CVE-2020-7224) where the initial fix was found to be incomplete. The issue specifically relates to how the client handles OpenSSL parameters that could be altered from their issued value set (Aviatrix Docs).

Impact

The vulnerability could allow unauthorized code execution through dangerous OpenSSL parameters that are not properly authorized. This affects installations across multiple operating systems including macOS, Linux, and Windows, potentially enabling elevation of privilege attacks (Aviatrix Docs).

Exploitability

The vulnerability requires local access to exploit and involves manipulation of OpenSSL parameters. It was rated with a high severity CVSS score of 7.5, indicating significant potential for exploitation (CISA Bulletin).

Mitigation and workarounds

The vulnerability was addressed by upgrading to Aviatrix VPN Client version 2.10.7 or later. Additionally, administrators must configure OpenVPN minimum client version to 2.10.7 in the Controller. For complete protection, it's recommended to upgrade both the Client VPN to version 2.10.7 and the Controller & Gateway to version 5.3 or later (Aviatrix Docs).

Community reactions

The vulnerability was responsibly disclosed by Rich Mirch, Senior Adversarial Engineer - TeamARES from Critical Start, Inc., demonstrating active security research in the VPN client space (Aviatrix Docs).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util-bdb
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management