Arista
Arista NG Firewall: vulnerabilidades y CVE
Arista NG Firewall tiene 20 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25624 | Media (5.8) | 0.27% | — | 5 jun 2026 | An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables… |
| CVE-2026-25623 | Alta (7) | 0.58% | — | 5 jun 2026 | An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this… |
| CVE-2026-25622 | Alta (7) | 0.97% | — | 5 jun 2026 | A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user… |
| CVE-2026-25621 | Alta (7) | 0.38% | — | 5 jun 2026 | A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier… |
| CVE-2026-25620 | Alta (7) | 0.97% | — | 5 jun 2026 | An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version… |
| CVE-2025-2767 | Crítica (9.6) | 0.64% | — | 23 abr 2025 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user… |
| CVE-2024-9188 | Alta (8.8) | 0.48% | — | 10 ene 2025 | Specially constructed queries cause cross platform scripting leaking administrator tokens |
| CVE-2024-9134 | Alta (8.3) | 0.62% | — | 10 ene 2025 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying… |
| CVE-2024-9133 | Media (5.6) | 0.16% | — | 10 ene 2025 | A user with administrator privileges is able to retrieve authentication tokens |
| CVE-2024-9132 | Crítica (9.8) | 0.69% | — | 10 ene 2025 | The administrator is able to configure an insecure captive portal script |
| CVE-2024-9131 | Alta (7.2) | 1.4% | — | 10 ene 2025 | A user with administrator privileges can perform command injection |
| CVE-2024-47520 | Alta (7.6) | 0.41% | — | 10 ene 2025 | A user with advanced report application access rights can perform actions for which they are not authorized |
| CVE-2024-47519 | Alta (7.1) | 0.34% | — | 10 ene 2025 | Backup uploads to ETM subject to man-in-the-middle interception |
| CVE-2024-47518 | Alta (7.6) | 0.43% | — | 10 ene 2025 | Specially constructed queries targeting ETM could discover active remote access sessions |
| CVE-2024-47517 | Media (6.8) | 0.40% | — | 10 ene 2025 | Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access |
| CVE-2024-12832 | Media (6.3) | 0.50% | — | 20 dic 2024 | Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations… |
| CVE-2024-12831 | Alta (7.8) | 0.16% | — | 20 dic 2024 | Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must… |
| CVE-2024-12830 | Alta (7.3) | 1.0% | — | 20 dic 2024 | Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall.… |
| CVE-2024-12829 | Alta (8.8) | 1.3% | — | 20 dic 2024 | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall.… |
| CVE-2024-27889 | Alta (8.8) | 8.8% | — | 4 mar 2024 | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.