No analysis available yet.
Vendor Solution
The recommended resolution is to upgrade to NGFW Version 17.4.1 at your earliest convenience.
Vendor Workaround
If managing an active NGFW 17.4.0 deployment, disable the Captive Portal Basic Login configuration profile parameter.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed. | |
| Title | Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-06-05T20:23:31.151Z
Reserved: 2026-02-03T22:23:04.359Z
Link: CVE-2026-25620
Updated: 2026-06-05T20:23:28.256Z
Status : Awaiting Analysis
Published: 2026-06-05T20:17:30.447
Modified: 2026-06-05T20:48:41.560
Link: CVE-2026-25620
No data.
OpenCVE Enrichment
No data.