CVE-2025-2171 Details
Description
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
A vulnerability exists in Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0, where rate limiting is not enforced on password reset requests. This oversight allows attackers to brute force the 6-digit password reset PIN, with approximately 888,888 possible combinations. The lack of effective token management creates a window of opportunity for account takeover within 15 minutes of initiating a password reset.
Users can update to Aviatrix Controller versions 8.0.0, 7.2.5090, or 7.1.4208 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2025CISA-ADP
Assessed Jun 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cloud.google.com/blog/topics/threat-intelligence/remote-code-execution-aviatrix-controller | [email protected] | BundleTechnical Analysis |
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0003.md | [email protected] | Not Applicable |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Aviatrix Controller | < 7.1.4208 (semver) < 7.2.5090 (semver) < 8.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | CVE Modified | [email protected] |
| Jun 23, 2025 | New CVE Received | [email protected] |
Volerion