SQL Injection Vulnerability in Arista NG Firewall's ReportEntry Component
CVE-2024-12832

6.3MEDIUM

Key Information:

Vendor
CVE Published:
20 December 2024

What is CVE-2024-12832?

CVE-2024-12832 is a critical SQL Injection vulnerability identified in the ReportEntry class of the Arista NG Firewall. This flaw permits remote attackers, post-authentication, to craft malicious inputs that manipulate SQL queries, paving the way for arbitrary file creation and sensitive information disclosure. By exploiting this vulnerability, attackers can potentially execute arbitrary code running as the www-data user, which might lead to further compromise within affected installations. The vulnerability requires careful validation of user-provided strings, which is currently lacking in the affected component.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.