CVE-2025-6979

8.8

Arista Networks · Arista Edge Threat Management - Arista Next Generation Firewall

A vulnerability in the Captive Portal component of Arista Next Generation Firewall allows for authentication bypass.

Executive summary

An authentication bypass vulnerability in the Arista Next Generation Firewall Captive Portal exposes systems to potential unauthorized access and compromise.

Vulnerability

This vulnerability is classified as an improper authentication issue (CWE-287) affecting the Captive Portal functionality. It allows an unauthenticated attacker to bypass security controls and potentially gain unauthorized access to the system.

Business impact

Successful exploitation of this flaw could allow an attacker to gain unauthorized access to the network or internal services protected by the firewall, leading to data compromise or unauthorized administrative control. Given the high CVSS score of 8.8, this vulnerability represents a significant risk to organizational infrastructure and requires immediate attention to prevent potential service disruption or unauthorized data exfiltration.

Remediation

Immediate Action: Upgrade the Arista Next Generation Firewall to version 17.4 or later as recommended by the vendor.

Proactive Monitoring: Review firewall access logs for unusual login activity, specifically looking for traffic patterns that bypass standard authentication workflows.

Compensating Controls: Ensure that management interfaces are restricted to trusted network segments and utilize network access control lists to limit the exposure of the affected Captive Portal until the update is deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates a swift response from IT security teams. Organizations utilizing Arista Edge Threat Management should prioritize the transition to version 17.4 immediately to remediate this authentication flaw and neutralize the risk of unauthorized access.

More Arista Networks CVEs

Sources

Originally found and disclosed by Arista would like to acknowledge and thank Gereon Huppertz working with Trend Zero Day Initiative for reporting CVE-2025, per the CVE Program record.