Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25082 | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. |
Solution
The recommended resolution is to upgrade to the version indicated below and apply the hotfix at your earliest convenience. * 17.1 Upgrade * 17.0 (requires Hotfix) To resolve click the following link for instructions to either upgrading or apply a hotfix patch: Click here for the hotfix and instructions on resolving this issue https://wiki.edge.arista.com/index.php/Patch_-_Report_vulnerability
Workaround
For the Reports application, for all Reports Users, disable Online Access. To do this: 2. As the NGFW administrator, log into the UI and go to the Reports application. 3. For all users with the Online Access checkbox (red box) enabled, uncheck it. 4. Click Save.
Wed, 22 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista ng Firewall |
|
| CPEs | cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arista
Arista ng Firewall |
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2024-08-02T00:41:55.605Z
Reserved: 2024-02-26T18:06:32.160Z
Link: CVE-2024-27889
Updated: 2024-08-02T00:41:55.605Z
Status : Analyzed
Published: 2024-03-04T20:15:50.503
Modified: 2025-10-22T13:49:56.060
Link: CVE-2024-27889
No data.
OpenCVE Enrichment
No data.
EUVD