Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the User-Agent HTTP header. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24407.
The application improperly validates user-supplied data in the HTTP User-Agent header, which enables arbitrary script injection (XSS). An attacker can craft an HTTP request with a specially modified User-Agent header containing a malicious payload. The vulnerability is classified as Stored or Reflected XSS (CWE-79) leading to server-side code execution. Minimal user interaction is required to carry out the attack.
An attacker can execute arbitrary code in the context of the root account, thereby gaining full control over the attacked device or system. This results in complete compromise of the system's confidentiality, integrity, and availability, and potentially the network protected by the firewall.
Apply patches available from the vendor according to the references. Detailed information about patch versions is available in the Zero Day Initiative advisory at https://www.zerodayinitiative.com/advisories/ZDI-25-181/
Arista NG Firewall — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HArista Ng Firewall
APPArista17.1.1
Related vulnerabilities
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Aris...
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge T...
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Ar...
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Gener...
The administrator is able to configure an insecure captive portal script