Project Subscriptions
No data.
No advisories yet.
Solution
The recommended resolution is to upgrade to NGFW Version 17.4.1 at your earliest convenience.
Workaround
If managing an active NGFW 17.4.0 deployment, disable the Captive Portal Basic Login configuration profile parameter.
Fri, 05 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed. | |
| Title | Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-06-05T20:23:31.151Z
Reserved: 2026-02-03T22:23:04.359Z
Link: CVE-2026-25620
Updated: 2026-06-05T20:23:28.256Z
Status : Awaiting Analysis
Published: 2026-06-05T20:17:30.447
Modified: 2026-06-05T20:48:41.560
Link: CVE-2026-25620
No data.
OpenCVE Enrichment
Updated: 2026-06-05T22:15:06Z