CVE-2020-13412: Aviatrix Controller

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.

Affected products

  • Aviatrix Controller: before 5.4.1204 (fixed in 5.4.1204)

Published 2020-05-22. Last modified 2026-06-17.