Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
History

Wed, 22 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista ng Firewall
CPEs cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:*
Vendors & Products Arista
Arista ng Firewall

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published: 2024-03-04T19:32:33.109Z

Updated: 2024-08-02T00:41:55.605Z

Reserved: 2024-02-26T18:06:32.160Z

Link: CVE-2024-27889

cve-icon Vulnrichment

Updated: 2024-08-02T00:41:55.605Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-04T20:15:50.503

Modified: 2025-10-22T13:49:56.060

Link: CVE-2024-27889

cve-icon Redhat

No data.