CVE-2025-2171 Information
Jun 26, 2025
cve
Description
Aviatrix Controller versions prior to 7.1.4208 7.2.5090 and 8.0.0 do not enforce rate limiting on password reset attempts allowing adversaries to brute force guess the 6-digit password reset PIN
Reference
https://cloud.google.com/blog/topics/threat-intelligence/remote-code-execution-aviatrix-controller https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0003.md
Share on: