SQL Injection Vulnerability in Arista NG Firewall's ReportEntry Component
CVE-2024-12832
What is CVE-2024-12832?
CVE-2024-12832 is a critical SQL Injection vulnerability identified in the ReportEntry class of the Arista NG Firewall. This flaw permits remote attackers, post-authentication, to craft malicious inputs that manipulate SQL queries, paving the way for arbitrary file creation and sensitive information disclosure. By exploiting this vulnerability, attackers can potentially execute arbitrary code running as the www-data user, which might lead to further compromise within affected installations. The vulnerability requires careful validation of user-provided strings, which is currently lacking in the affected component.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
