Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Arista
Published: 2024-03-04T19:32:33.109Z
Updated: 2024-06-04T17:47:15.432Z
Reserved: 2024-02-26T18:06:32.160Z
Link: CVE-2024-27889
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-03-04T20:15:50.503
Modified: 2024-03-05T13:41:01.900
Link: CVE-2024-27889
JSON object: View
Redhat Information
No data.
CWE