Impact
A Reports application within Arista Edge Threat Management Next Generation Firewall version 17.4.0 contains insecure input validation that could allow an attacker to inject operating‑system commands. The vulnerability is classified as CWE‑78, indicating potential OS command injection. While the CVE description does not explicitly confirm that remote code execution is achievable, the insecure input handling suggests that injected commands may be executed with the privileges of the firewall process, potentially affecting the confidentiality, integrity, and availability of the device.
Affected Systems
The flaw is limited to the NGFW release 17.4.0. Earlier software releases are not affected. The product is Arista Networks Edge Threat Management – Arista Next Generation Firewall.
Risk and Exploitability
The CVSS score of 7 reflects a high severity for this issue. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate exploitation likelihood. The likelihood of exploitation depends on an attacker’s ability to reach the Reports application, which normally requires administrative access. By preventing unauthorized administrative access as recommended in the workaround, the attack surface is reduced until the official patch is applied.
OpenCVE Enrichment