CVE-2025-37170: Authenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management Interface
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-37170?
CVE-2025-37170 is classified as a critical vulnerability due to its potential for authenticated command injection.
How do I fix CVE-2025-37170?
To fix CVE-2025-37170, ensure you update to the latest patched version of Arista Networks AOS-8.
Who is affected by CVE-2025-37170?
Arista Networks AOS-8 users who have the web-based management interface enabled are affected by CVE-2025-37170.
What type of vulnerability is CVE-2025-37170?
CVE-2025-37170 is an authenticated command injection vulnerability.
Can CVE-2025-37170 be exploited remotely?
CVE-2025-37170 requires authenticated access, meaning it cannot be exploited remotely without valid credentials.