{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-6980",
        "assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
        "state": "PUBLISHED",
        "assignerShortName": "Arista",
        "dateReserved": "2025-07-01T16:53:05.372Z",
        "datePublished": "2025-10-23T18:41:47.326Z",
        "dateUpdated": "2025-10-23T18:59:58.995Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Arista Edge Threat Management - Arista Next Generation Firewall",
                    "vendor": "Arista Networks",
                    "versions": [
                        {
                            "lessThanOrEqual": "17.3.1",
                            "status": "affected",
                            "version": "0.0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "configurations": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<h4>1) CVE-2025-6980 (ZDI-CAN-27006) - Captive Portal can expose sensitive information</h4><div><b>Required Configuration for Exploitation</b></div><div>&nbsp;</div><div>If the Captive Portal application is installed and enabled, the systems are vulnerable.</div><div>&nbsp;</div><div>To access this information:</div><ol><li>As the NGFW administrator, log into the UI and navigate to the Captive Portal application.</li><li>If the Captive Portal application is not installed, the system is not vulnerable.</li><li>If Captive Portal is not enabled, the system is not vulnerable.</li></ol><p><img alt=\"Captive Portal as enabled\" src=\"https://www.arista.com/assets/images/article/SA-123-1.png\"></p><p>The above shows Captive Portal as enabled.</p><h4>Indicators of Compromise</h4><div>No evidence of compromise exists.</div><div>&nbsp;</div><h4>Mitigation</h4><p>Disable Captive Portal.</p><div>As the NGFW administrator, log into the UI and navigate to the Captive Portal application.</div><ol><li>If the Captive Portal application is not installed, the system is not vulnerable.</li><li>If Captive Portal is not enabled, the system is not vulnerable.</li><li>Move the Enabled slider to disabled.</li><li>Click Save</li><li>Disable Captive Portal.</li></ol><p><img alt=\"Captive Portal as enabled\" src=\"https://www.arista.com/assets/images/article/SA-123-2.png\"></p><div>&nbsp;</div><h4>2) CVE-2025-6979 (ZDI-CAN-27007) - Captive Portal can allow authentication bypass</h4><div><b>Required Configuration for Exploitation</b></div><div>&nbsp;</div><div>If the Captive Portal application is installed and enabled, the systems are vulnerable.</div><div>&nbsp;</div><div>To access this information:</div><ol><li>As the NGFW administrator, log into the UI and navigate to the Captive Portal application.</li><li>If the Captive Portal application is not installed, the system is not vulnerable.</li><li>If Captive Portal is not enabled, the system is not vulnerable.</li></ol><p><img alt=\"Captive Portal as enabled\" src=\"https://www.arista.com/assets/images/article/SA-123-1.png\"></p><h4>Indicators of Compromise</h4><p>No evidence of compromise exists.</p><h4>Mitigation</h4><p>Disable Captive Portal.</p><div>As the NGFW administrator, log into the UI and navigate to the Captive Portal application.</div><ol><li>If the Captive Portal application is not installed, the system is not vulnerable.</li><li>If Captive Portal is not enabled, the system is not vulnerable.</li><li>Move the Enabled slider to disabled.</li><li>Click Save</li><li>Disable Captive Portal.</li></ol><p><img alt=\"Captive Portal as enabled\" src=\"https://www.arista.com/assets/images/article/SA-123-2.png\"></p><h4>3) CVE-2025-6978 (ZDI-CAN-27310) - Diagnostics command injection vulnerability</h4><p><b>Required Configuration for Exploitation</b></p><ol><li>A successful attack requires administrative access to the NGFW UI.</li></ol><br>"
                        }
                    ],
                    "value": "1) CVE-2025-6980 (ZDI-CAN-27006) - Captive Portal can expose sensitive informationRequired Configuration for Exploitation\n\n \n\nIf the Captive Portal application is installed and enabled, the systems are vulnerable.\n\n \n\nTo access this information:\n\n  *  As the NGFW administrator, log into the UI and navigate to the Captive Portal application.\n  *  If the Captive Portal application is not installed, the system is not vulnerable.\n  *  If Captive Portal is not enabled, the system is not vulnerable.\n\n\nThe above shows Captive Portal as enabled.\n\nIndicators of CompromiseNo evidence of compromise exists.\n\n \n\nMitigationDisable Captive Portal.\n\nAs the NGFW administrator, log into the UI and navigate to the Captive Portal application.\n\n  *  If the Captive Portal application is not installed, the system is not vulnerable.\n  *  If Captive Portal is not enabled, the system is not vulnerable.\n  *  Move the Enabled slider to disabled.\n  *  Click Save\n  *  Disable Captive Portal.\n\n\n \n\n2) CVE-2025-6979 (ZDI-CAN-27007) - Captive Portal can allow authentication bypassRequired Configuration for Exploitation\n\n \n\nIf the Captive Portal application is installed and enabled, the systems are vulnerable.\n\n \n\nTo access this information:\n\n  *  As the NGFW administrator, log into the UI and navigate to the Captive Portal application.\n  *  If the Captive Portal application is not installed, the system is not vulnerable.\n  *  If Captive Portal is not enabled, the system is not vulnerable.\n\n\nIndicators of CompromiseNo evidence of compromise exists.\n\nMitigationDisable Captive Portal.\n\nAs the NGFW administrator, log into the UI and navigate to the Captive Portal application.\n\n  *  If the Captive Portal application is not installed, the system is not vulnerable.\n  *  If Captive Portal is not enabled, the system is not vulnerable.\n  *  Move the Enabled slider to disabled.\n  *  Click Save\n  *  Disable Captive Portal.\n\n\n3) CVE-2025-6978 (ZDI-CAN-27310) - Diagnostics command injection vulnerabilityRequired Configuration for Exploitation\n\n  *  A successful attack requires administrative access to the NGFW UI."
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "cpeMatch": [
                                {
                                    "criteria": "cpe:2.3:a:arista_networks:arista_edge_threat_management_-_arista_next_generation_firewall:*:*:*:*:*:*:*:*",
                                    "versionEndIncluding": "17.3.1",
                                    "versionStartIncluding": "0.0",
                                    "vulnerable": true
                                }
                            ],
                            "negate": false,
                            "operator": "OR"
                        }
                    ],
                    "operator": "OR"
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Arista would like to acknowledge and thank Gereon Huppertz working with Trend Zero Day Initiative for reporting CVE-2025-6980"
                }
            ],
            "datePublic": "2025-10-21T15:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">Captive Portal can expose sensitive information</span><br>"
                        }
                    ],
                    "value": "Captive Portal can expose sensitive information"
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-410",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-410 Information Elicitation"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-200",
                            "description": "CWE-200 Exposure of Sensitive Information to an Unauthorized Actor",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
                "shortName": "Arista",
                "dateUpdated": "2025-10-23T18:41:47.326Z"
            },
            "references": [
                {
                    "url": "https://https://www.arista.com/en/support/advisories-notices/security-advisory/22535-security-advisory-0123"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<p>The recommended resolution is to upgrade to the version indicated below at your earliest convenience.</p><ul><li>17.4 Upgrade</li></ul>"
                        }
                    ],
                    "value": "The recommended resolution is to upgrade to the version indicated below at your earliest convenience.\n\n  *  17.4 Upgrade"
                }
            ],
            "source": {
                "advisory": "123",
                "defect": [
                    "NGFW-15197"
                ],
                "discovery": "EXTERNAL"
            },
            "title": "Captive Portal can expose sensitive information",
            "workarounds": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">Do not allow non-authorized administrative access or access to the administrative browser.</span><br>"
                        }
                    ],
                    "value": "Do not allow non-authorized administrative access or access to the administrative browser."
                }
            ],
            "x_generator": {
                "engine": "Vulnogram 0.4.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-10-23T18:59:53.166328Z",
                                "id": "CVE-2025-6980",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-10-23T18:59:58.995Z"
                }
            }
        ]
    }
}