
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Aviatrix Controller before R5.4.1290 that involves an insecure sudo rule configuration. Specifically, a user exists on the system that can execute all commands as any user, creating a significant privilege escalation risk (NVD).
The vulnerability has been assigned a CVSS v3.1 Base Score of 8.8 HIGH with a vector string of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The CVSS v2.0 Base Score is 9.0 HIGH with a vector string of (AV:N/AC:L/Au:S/C:C/I:C/A:C). This indicates a serious security issue with high impact potential across confidentiality, integrity, and availability (NVD).
The vulnerability allows a user with limited privileges to execute any command as any user on the system, including root. This effectively bypasses intended access controls and security boundaries, potentially giving an attacker complete control over the affected system (NVD).
The vulnerability requires an attacker to have valid credentials on the system but is considered relatively easy to exploit once this access is obtained. The attacker can leverage the insecure sudo configuration to elevate their privileges and execute arbitrary commands (NVD).
The vulnerability has been fixed in Aviatrix Controller version R5.4.1290 and later. Organizations should upgrade to a patched version to address this security issue (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."