CVE-2020-13415: Aviatrix Controller

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.

Affected products

  • Aviatrix Controller: up to and including 5.1

Published 2020-05-22. Last modified 2026-06-17.