The administrator is able to configure an insecure captive portal script
Fixes

Solution

The recommended resolution for all issues documented above is to upgrade to the version indicated below at your earliest convenience. * 17.2 Upgrade


Workaround

Disable custom page. * As the NGFW administrator, log into the UI and navigate to the Captive Portal application. * Select either “Basic Message” or “Basic Login” * Click Save.

History

Mon, 29 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista ng Firewall
CPEs cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:*
Vendors & Products Arista
Arista ng Firewall

Mon, 13 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jan 2025 21:45:00 +0000

Type Values Removed Values Added
Description The administrator is able to configure an insecure captive portal script
Title The administrator is able to configure an insecure captive portal script
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2025-01-13T17:49:01.649Z

Reserved: 2024-09-23T22:01:00.888Z

Link: CVE-2024-9132

cve-icon Vulnrichment

Updated: 2025-01-13T17:48:57.348Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-10T22:15:26.783

Modified: 2025-09-29T12:34:31.980

Link: CVE-2024-9132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.