Description
An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.
Published: 2026-06-05
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An administrative cross‑site scripting flaw is present in the dashboard layout of Arista Edge Threat Management NGFW. Unvalidated input from variables that are echoed back to the administrative interface allows an attacker to inject arbitrary script into the web UI. The injected code can overwrite controls or trigger functions within the dashboard, potentially leading to unauthorized actions performed under the privileges of the administrative user, but the vulnerability does not provide a direct path to arbitrary code execution on the underlying operating system.

Affected Systems

The vulnerability applies to Arista Networks’ Edge Threat Management – Arista Next Generation Firewall. The affected version range is not specified beyond the recommendation to upgrade to NGFW 17.4.1; users of earlier releases of the NGFW should assume the defect is present. No other vendors or products are listed.

Risk and Exploitability

The CVSS v3 score of 5.8 denotes a moderate severity. The EPSS score is not published, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the wild to date. The likely attack vector involves authenticated administrative access to the web UI, although the flaw could be exploited by forging requests from an attacker’s client if authentication can be spoofed or bypassed. As the flaw requires user interaction with the administrative browser, the likelihood of exploitation depends on the privilege level of attackers who can reach the device’s management interface.

Generated by OpenCVE AI on June 5, 2026 at 21:36 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to NGFW Version 17.4.1 at your earliest convenience.


Vendor Workaround

Per operational best practice security models, do not allow unauthorized administrative access to the administrative browser.


OpenCVE Recommended Actions

  • Upgrade to NGFW Version 17.4.1 as released by Arista.
  • Disable or restrict access to the administrative web interface to trusted networks or devices only.
  • Enforce strict authentication and role‑based access control so that only necessary administrative accounts can reach the UI, and monitor for any anomalous script injection attempts.

Generated by OpenCVE AI on June 5, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Arista ng Firewall
CPEs cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:*
Vendors & Products Arista ng Firewall

Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista edge Threat Management
Vendors & Products Arista
Arista edge Threat Management

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
Description An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.
Title Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Arista Edge Threat Management Ng Firewall
cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-06-05T20:28:03.806Z

Reserved: 2026-02-03T22:23:04.359Z

Link: CVE-2026-25624

cve-icon Vulnrichment

Updated: 2026-06-05T20:27:59.744Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T20:17:31.160

Modified: 2026-06-08T19:08:16.633

Link: CVE-2026-25624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T11:15:49Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')