ZDI-CAN-21954: ZDI-24-364: Arista NG Firewall ReportEntry SQL Injection Remote Code Execution Vulnerability
Published Apr 9, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27889.
Affected Software
1 affected component
Arista NG Firewall
Event History
Apr 9, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-21954?
The severity of ZDI-CAN-21954 is rated 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-21954?
To fix ZDI-CAN-21954, apply the latest security updates provided by Arista for the NG Firewall.
3
Who can exploit ZDI-CAN-21954?
ZDI-CAN-21954 can be exploited by remote attackers who have authentication access to the affected installations.
4
What is the potential impact of ZDI-CAN-21954?
The potential impact of ZDI-CAN-21954 includes the execution of arbitrary code on affected installations.
5
Is ZDI-CAN-21954 related to any CVEs?
Yes, ZDI-CAN-21954 is associated with CVE-2024-27889.