CVE-2020-13413: Aviatrix Controller

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.

Affected products

  • Aviatrix Controller: before 5.4.1204 (fixed in 5.4.1204)
  • Aviatrix VPN Client: version 2.8.2 only

Published 2020-05-22. Last modified 2026-06-17.