CRITICAL🇵🇱 Wersja polska

CVE-2025-2767

CVSS 9.6v3.1pub. 2025-04-23upd. 2025-08-14

Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the User-Agent HTTP header. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24407.

🤖 AI Analysis
How it works

The application improperly validates user-supplied data in the HTTP User-Agent header, which enables arbitrary script injection (XSS). An attacker can craft an HTTP request with a specially modified User-Agent header containing a malicious payload. The vulnerability is classified as Stored or Reflected XSS (CWE-79) leading to server-side code execution. Minimal user interaction is required to carry out the attack.

Impact

An attacker can execute arbitrary code in the context of the root account, thereby gaining full control over the attacked device or system. This results in complete compromise of the system's confidentiality, integrity, and availability, and potentially the network protected by the firewall.

Mitigation & patch

Apply patches available from the vendor according to the references. Detailed information about patch versions is available in the Zero Day Initiative advisory at https://www.zerodayinitiative.com/advisories/ZDI-25-181/

Who is affected

Arista NG Firewall — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Arista Ng Firewall

    APP
    Arista
    17.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSSFirewall
CWE
References

Related vulnerabilities

CVE-2026-25622HIGH7.0same product

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Aris...

CVE-2026-25623HIGH7.0same product

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge T...

CVE-2026-25620HIGH7.0same product

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Ar...

CVE-2026-25621HIGH7.0same product

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Gener...

CVE-2024-9132HIGH8.1same product

The administrator is able to configure an insecure captive portal script