📦

controller

Vendor: aviatrix

Actively Exploited 2 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 3 Remote Access
Total CVEs 22 Total Indexed
Avg. EPSS 5.98% Exploit Prob.
Latest CVE CVE-2026-5065 May 27

Security Vulnerability Index

Page 3 / 3
4.3 CVSS

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

EPSS: 0.79%
3.7 CVSS

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

EPSS: 0.47%
Critical Target
9.8 CVSS
CVE-2021-40870
RCE Exploit Found

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

EPSS: 93.02%
7.5 CVSS

Insecure File Permissions exist in Aviatrix Controller 5.3.1516. Several world writable files and directories were found in the controller resource. Note: All Aviatrix appliances are fully encrypted. This is an extra layer of security.

EPSS: 1.56%
9.8 CVSS

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

EPSS: 1.74%
7.5 CVSS

An issue was discovered in Aviatrix Controller before R6.0.2483. Multiple executable files, that implement API endpoints, do not require a valid session ID for access.

EPSS: 1.16%
7.5 CVSS

An issue was discovered in Aviatrix Controller before R5.3.1151. Encrypted key values are stored in a readable file.

EPSS: 0.91%
7.5 CVSS

An issue was discovered in Aviatrix Controller before R5.3.1151. An encrypted file containing credentials to unrelated systems is protected by a three-character key.

EPSS: 1.46%
7.5 CVSS

An issue was discovered in Aviatrix Controller before R5.4.1290. The htaccess protection mechanism to prevent requests to directories can be bypassed for file downloading.

EPSS: 1.49%
8.8 CVSS

An issue was discovered in Aviatrix Controller before R5.4.1290. There is an insecure sudo rule: a user exists that can execute all commands as any user on the system.

EPSS: 1.44%