CVE-2020-13415
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
HIGH · CVSS 7.5
EPSS 0.00132
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules3
YARA rules0