Beveiligingsadvies

CVE-2024-27889

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-03-04 19:32:33
Laatst bijgewerkt 2024-08-02 00:41:55
Toegewezen door Arista
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.