An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://docs.aviatrix.com/HowTos/security_bulletin_article.html#observable-response-discrepancy-from-api | vendor advisory |
https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/ | third party advisory exploit |