Security Advisory

CVE-2020-13415

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-05-22 20:48:23
Last updated 2024-08-04 12:18:17
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.