Vulnerability identifier: #VU109378
Vulnerability risk: Medium
CVSSv4.0: 6.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-284
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Arista Edge Threat Management - Arista NG Firewall (NGFW)
Server applications /
IDS/IPS systems, Firewalls and proxy servers
Vendor: Arista Networks
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user with advanced report application access rights can bypass implemented security restrictions and gain unauthorized access to the application.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Arista Edge Threat Management - Arista NG Firewall (NGFW): before 17.2
External links
https://www.arista.com/en/support/advisories-notices/security-advisory/20454-security-advisory-0105
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.