LiveActive security incident?Get immediate response
CVE Record

CVE-2020-26553: An issue was discovered in Aviatrix Controller before R6.0.2483.

An issue was discovered in Aviatrix Controller before R6.0.2483. Several APIs contain functions that allow arbitrary files to be uploaded to the web tree.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Aviatrix Controller versions before R6.0.2483 had API functions that could allow arbitrary file uploads into the web tree. For executives, the concern is unauthorized content or potentially hostile files placed where the Controller serves web content. The public bundle does not provide CVSS, exploit details, or proof of active exploitation.

Executive priority

Prioritize remediation for any exposed Aviatrix Controller because arbitrary file upload on a cloud networking controller can create meaningful compromise risk. Urgency is lower where the Controller is already updated or tightly isolated, but version verification should be prompt.

Technical view

CVE-2020-26553 describes arbitrary file upload via several Aviatrix Controller APIs before R6.0.2483, with uploaded files reaching the web tree. The sources do not specify authentication requirements, endpoint names, file execution behavior, CVSS metrics, or CWE mapping, so impact depends on deployment exposure and server handling of uploaded files.

Likely exposure

Exposure is limited to Aviatrix Controller installations before R6.0.2483. Risk is higher where the Controller or its APIs are reachable from untrusted networks. The source bundle does not identify affected cloud environments, configurations, or CPEs.

Exploitation context

The provided sources do not show active exploitation, and the CVE is not listed as KEV in the bundle. No exploit code, attack chain, or required privileges are provided. Treat exploitability details as incomplete.

Researcher notes

Key missing details are authentication requirements, affected API names, file type constraints, and whether uploaded files can execute server-side. Avoid assuming remote code execution from the CVE text alone; validate behavior only in authorized lab environments.

Mitigation direction

  • Upgrade Aviatrix Controller to R6.0.2483 or later if vendor guidance confirms applicability.
  • Review Aviatrix advisory guidance for fixed builds and any interim controls.
  • Restrict Controller and API access to trusted administrative networks.
  • Inspect web-accessible directories for unexpected uploaded files.

Validation and detection

  • Inventory Aviatrix Controller versions and flag any build before R6.0.2483.
  • Confirm whether Controller APIs are internet-exposed or reachable by broad internal networks.
  • Review Controller web tree contents for unauthorized or recently added files.
  • Check logs for unusual API upload activity, if relevant logs are retained.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-26553 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.