Impact
The encrypted password command injection flaw exists within the Captive Portal framework of Arista Edge Threat Management NGFW. An attacker who can influence the password handling logic can inject arbitrary system commands, leading to potential remote code execution or unintended configuration changes. This weakness is classified as CWE-78 and can compromise the integrity and availability of the firewall.
Affected Systems
The flaw only affects Arista Edge Threat Management – Arista Next Generation Firewall (NGFW) version 17.4.0; all earlier releases remain unaffected. The vulnerability exists specifically in the Captive Portal configuration component of the NGFW.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be network‑based, targeting the Captive Portal configuration interface that is typically reachable only from trusted administrative networks. If exploited, it could allow an attacker to execute arbitrary commands on the device.
OpenCVE Enrichment