Command Injection Vulnerability in Aviatrix Controller Products
CVE-2025-2172
6.6MEDIUM
What is CVE-2025-2172?
Aviatrix Controller versions preceding 7.1.4208, 7.2.5090, and 8.0.0 improperly handle user input by failing to adequately sanitize it before utilizing it in command line utilities. This flaw allows attackers to exploit special characters in filenames to execute arbitrary commands, potentially compromising system integrity and security. Organizations using affected versions should prioritize patching and review their input validation protocols to mitigate the risk associated with this vulnerability.
Affected Version(s)
Controller 7.1.4208
Controller 7.1.4208
Controller 7.2.5090
References
CVSS V4
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved