VendorsAristang_firewallall versions
Vulnerabilities

Arista NG Firewall

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2024-9132
The administrator is able to configure an insecure captive portal script
Published 2025-01-10 · Analyzed
9.8EPSS 0.007
CVE-2025-2767
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability
Published 2025-04-23 · Analyzed
9.6EPSS 0.006
CVE-2024-27889
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).
Published 2024-03-04 · Analyzed
8.8EPSS 0.088
CVE-2024-12829
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability
Published 2024-12-20 · Analyzed
8.8EPSS 0.013
CVE-2024-9188
Specially constructed queries cause cross platform scripting leaking administrator tokens
Published 2025-01-10 · Analyzed
8.8EPSS 0.005
CVE-2024-9134
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
Published 2025-01-10 · Analyzed
8.3EPSS 0.006
CVE-2024-12832
Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability
Published 2024-12-20 · Analyzed
8.3EPSS 0.005
CVE-2024-47519
Backup uploads to ETM subject to man-in-the-middle interception
Published 2025-01-10 · Analyzed
8.3EPSS 0.003
CVE-2024-12830
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability
Published 2024-12-20 · Analyzed
8.1EPSS 0.010
CVE-2024-12831
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability
Published 2024-12-20 · Analyzed
7.8EPSS 0.002
CVE-2024-47518
Specially constructed queries targeting ETM could discover active remote access sessions
Published 2025-01-10 · Analyzed
7.6EPSS 0.004
CVE-2024-47520
A user with advanced report application access rights can perform actions for which they are not authorized
Published 2025-01-10 · Analyzed
7.6EPSS 0.004
CVE-2024-9131
A user with administrator privileges can perform command injection
Published 2025-01-10 · Analyzed
7.2EPSS 0.014
CVE-2026-25620
Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
Published 2026-06-05 · Analyzed
7.0EPSS 0.099
CVE-2026-25622
Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
Published 2026-06-05 · Analyzed
7.0EPSS 0.099
CVE-2026-25623
Arista Edge Threat Management NGFW UI Arbitrary Command Execution
Published 2026-06-05 · Analyzed
7.0EPSS 0.060
CVE-2026-25621
Arista Edge Threat Management NGFW Reports Application Insecure Input Validation
Published 2026-06-05 · Analyzed
7.0EPSS 0.002
CVE-2024-47517
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
Published 2025-01-10 · Analyzed
6.8EPSS 0.004
CVE-2024-9133
A user with administrator privileges is able to retrieve authentication tokens
Published 2025-01-10 · Analyzed
6.6EPSS 0.002
CVE-2026-25624
Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting
Published 2026-06-05 · Analyzed
5.8EPSS 0.002