First published: Thu Dec 19 2024(Updated: )
This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the uvm_login module. The issue results from incorrect authorization. An attacker can leverage this to escalate privileges to resources normally protected from the user.
Affected Software | Affected Version | How to fix |
---|---|---|
Arista Edge Threat Management - Arista NG Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-24-1720 is classified as a privilege escalation vulnerability.
To fix ZDI-24-1720, apply the latest updates provided by Arista for the NG Firewall.
ZDI-24-1720 affects installations of Arista NG Firewall.
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-24-1720.
ZDI-24-1720 is a local privilege escalation vulnerability.