Arista NG Firewall是美国Arista公司的一款 WEB 防火墙。 Arista Edge Threat Management - Arista NG Firewall存在安全漏洞,该漏洞源于具有高级报告应用程序访问权限的用户可以执行未经授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | Arista Edge Threat Management | 17.1.0 ~ 17.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-9188 | 8.8 HIGH | Specially constructed queries cause cross platform scripting leaking administrator tokens |
| CVE-2024-47519 | 8.3 HIGH | Backup uploads to ETM subject to man-in-the-middle interception |
| CVE-2024-9134 | 8.3 HIGH | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with ad |
| CVE-2024-9132 | 8.1 HIGH | The administrator is able to configure an insecure captive portal script |
| CVE-2024-9131 | 7.2 HIGH | A user with administrator privileges can perform command injection |
| CVE-2024-47517 | 6.8 MEDIUM | Expired and unusable administrator authentication tokens can be revealed by units that hav |
| CVE-2024-9133 | 6.6 MEDIUM | A user with administrator privileges is able to retrieve authentication tokens |
| CVE-2024-5872 | 6.5 MEDIUM | On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN t |
| CVE-2024-47518 | 6.4 MEDIUM | Specially constructed queries targeting ETM could discover active remote access sessions |
| CVE-2024-6437 | 5.8 MEDIUM | On affected platforms running Arista EOS with one of the following features configured to |
| CVE-2024-7142 | 4.6 MEDIUM | On Arista CloudVision Appliance (CVA) affected releases running on appliances that support |
| CVE-2024-7095 | 4.3 MEDIUM | On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit ma |
No comments yet