CVE-2024-27889: Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27889?
CVE-2024-27889 has been classified with a high severity due to its potential for SQL injection exploitation.
How do I fix CVE-2024-27889?
To fix CVE-2024-27889, it is recommended to update the Arista Edge Threat Management - Arista NG Firewall to the latest version provided by Arista.
Who is impacted by CVE-2024-27889?
Users with advanced report application access rights in the Arista Edge Threat Management - Arista NG Firewall can be impacted by CVE-2024-27889.
What types of attacks can CVE-2024-27889 enable?
CVE-2024-27889 can enable attackers to execute unauthorized SQL commands on the Arista Edge Threat Management application.
Is CVE-2024-27889 related to remote code execution?
CVE-2024-27889 is primarily a SQL injection vulnerability, which may lead to remote command execution depending on the underlying database configurations.