Loading
An issue was discovered in Aviatrix Gateway before 6.6.5712 and 6.7.x before 6.7.1376. Because Gateway API functions mishandle authentication, an authenticated VPN user can inject arbitrary commands.
Use CWE-287, Aviatrix vendor hub and Gateway product page to widen CVE-2022-38368 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-13417 and CVE-2020-13414 for nearby disclosures in the same product family.