Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-9188
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Specially constructed queries cause cross platform scripting leaking administrator tokens
0
Attacker Value
Unknown
CVE-2024-9134
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
0
Attacker Value
Unknown
CVE-2024-9133
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
A user with administrator privileges is able to retrieve authentication tokens
0
Attacker Value
Unknown
CVE-2024-9132
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
The administrator is able to configure an insecure captive portal script
0
Attacker Value
Unknown
CVE-2024-9131
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
A user with administrator privileges can perform command injection
0
Attacker Value
Unknown
CVE-2024-47520
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
A user with advanced report application access rights can perform actions for which they are not authorized
0
Attacker Value
Unknown
CVE-2024-47519
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Backup uploads to ETM subject to man-in-the-middle interception
0
Attacker Value
Unknown
CVE-2024-47518
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Specially constructed queries targeting ETM could discover active remote access sessions
0
Attacker Value
Unknown
CVE-2024-47517
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
0
Attacker Value
Unknown
CVE-2024-27889
Disclosure Date: March 04, 2024 (last updated March 05, 2024)
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
0