CVE-2020-13416: Aviatrix Controller

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.

Affected products

  • Aviatrix Controller: before 5.4.1066 (fixed in 5.4.1066)

Published 2020-05-22. Last modified 2026-06-17.