Captive Portal can allow authentication bypass

Project Subscriptions

Vendors Products
Ng Firewall Subscribe
Advisories

No advisories yet.

Fixes

Solution

The recommended resolution is to upgrade to the version indicated below at your earliest convenience. * 17.4 Upgrade


Workaround

MitigationDisable Captive Portal. As the NGFW administrator, log into the UI and navigate to the Captive Portal application. * If the Captive Portal application is not installed, the system is not vulnerable. * If Captive Portal is not enabled, the system is not vulnerable. * Move the Enabled slider to disabled. * Click Save * Disable Captive Portal.

History

Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista ng Firewall
Vendors & Products Arista
Arista ng Firewall

Thu, 23 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 19:00:00 +0000

Type Values Removed Values Added
Description Captive Portal can allow authentication bypass
Title Captive Portal can allow authentication bypass
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2025-10-23T18:59:32.658Z

Reserved: 2025-07-01T16:53:03.559Z

Link: CVE-2025-6979

cve-icon Vulnrichment

Updated: 2025-10-23T18:59:29.038Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-23T19:15:51.523

Modified: 2025-10-27T13:20:15.637

Link: CVE-2025-6979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-24T10:16:51Z

Weaknesses