PT-2025-26597 · Aviatrix · Aviatrix Controller
Louis Dion-Marcil
·
Published
2025-06-23
·
Updated
2025-07-31
·
CVE-2025-2172
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Aviatrix Controller versions prior to 7.1.4208
Aviatrix Controller versions prior to 7.2.5090
Aviatrix Controller versions prior to 8.0.0
Description:
The issue is related to the failure of the Aviatrix Controller to sanitize user input before passing it to command line utilities. This allows command injection via special characters in filenames.
Recommendations:
For versions prior to 7.1.4208, update to version 7.1.4208 or later.
For versions prior to 7.2.5090, update to version 7.2.5090 or later.
For versions prior to 8.0.0, update to version 8.0.0 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aviatrix Controller