Description
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
17.4.0 (custom)
Credits
Jon Williams & Ronan Kervella from Bishop Fox
References
www.arista.com/...rity-advisory/23399-security-advisory-0133