CVE-2025-25042: Authenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST Interface
A vulnerability in the AOS-CX REST interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation could allow an attacker to read encrypted credentials of other users on the switch, potentially leading to further unauthorized access or data breaches.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25042?
CVE-2025-25042 is classified as a medium severity vulnerability.
How do I fix CVE-2025-25042?
To fix CVE-2025-25042, it is recommended to update the AOS-CX software to the latest version provided by Arista.
Who is affected by CVE-2025-25042?
CVE-2025-25042 affects users of Arista AOS-CX with authenticated remote access capabilities.
What type of information can be exposed by CVE-2025-25042?
CVE-2025-25042 can expose sensitive information, including encrypted credentials of other users on the switch.
Can CVE-2025-25042 be exploited by unauthenticated users?
No, CVE-2025-25042 requires an authenticated remote attacker with low privileges to exploit the vulnerability.