CVE-2025-2172
Severity CVSS v4.0:
MEDIUM
Type:
CWE-78
OS Command Injections
Publication date:
23/06/2025
Last modified:
23/06/2025
Description
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Impact
Base Score 4.0
6.60
Severity 4.0
MEDIUM