PT-2024-22114 · Arista · Arista Ng Firewall

Published

2024-03-04

·

Updated

2025-10-22

·

CVE-2024-27889

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arista NG Firewall (affected versions not specified)
Description The issue concerns multiple SQL Injection vulnerabilities in the reporting application of the Arista Edge Threat Management - Arista NG Firewall. These vulnerabilities can be exploited by a user with advanced report application access rights, allowing them to execute commands on the underlying operating system with elevated privileges. The exploitation requires authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-27889
ZDI-24-364

Affected Products

Arista Ng Firewall