Description
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
17.4.0 (custom)
Credits
Jon Williams & Ronan Kervella from Bishop Fox
References
www.arista.com/...rity-advisory/22867-security-advisory-0133