CVE-2020-13417: Aviatrix Controller

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.

Affected products

  • Aviatrix Controller: before 5.3 (fixed in 5.3)
  • Aviatrix Gateway: before 5.3 (fixed in 5.3)
  • Aviatrix VPN Client: before 2.10.7 (fixed in 2.10.7)

Published 2020-05-22. Last modified 2026-06-17.