CVE-2025-2171: High severity Aviatrix Controller vulnerability
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2171?
CVE-2025-2171 is considered a medium severity vulnerability due to the lack of rate limiting on password reset attempts.
How do I fix CVE-2025-2171?
To mitigate CVE-2025-2171, update your Aviatrix Controller to version 7.1.4208, 7.2.5090, or later.
What types of attacks are possible with CVE-2025-2171?
CVE-2025-2171 allows adversaries to perform brute force attacks to guess the 6-digit password reset PIN due to the absence of rate limiting.
Which versions of Aviatrix Controller are affected by CVE-2025-2171?
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 are affected by CVE-2025-2171.
Is there a workaround for CVE-2025-2171 before updates are applied?
Currently, there are no known workarounds for CVE-2025-2171, and it is recommended to apply updates as soon as possible.