Home
HIGH: 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:PDefault status
affected
7.1.4208
unaffected
7.2.5090
unaffected
8.0.0
unaffected
Description
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
Problem types
CWE-307 Improper Restriction of Excessive Authentication Attempts
Product status
7.1.4208
7.2.5090
8.0.0
References
github.com/...Disclosures/blob/master/2025/MNDT-2025-0003.md
cloud.google.com/...emote-code-execution-aviatrix-controller