CVE-2024-27889

CVSS V2 None CVSS V3 None
Description
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
Overview
  • CVE ID
  • CVE-2024-27889
  • Assigner
  • Arista
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-03-04T19:32:33.109Z
  • Last Modified Date
  • 2024-06-04T17:47:15.432Z
History
Created Old Value New Value Data Type Notes
2024-06-26 01:35:12 Added to TrackCVE