Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-25620 | 1 Arista | 1 Edge Threat Management | 2026-06-07 | 6 Medium |
| An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed. | ||||
| CVE-2026-25621 | 1 Arista | 1 Edge Threat Management | 2026-06-07 | 6 Medium |
| A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed. | ||||
| CVE-2026-25622 | 1 Arista | 1 Edge Threat Management | 2026-06-07 | 6 Medium |
| A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands. | ||||
| CVE-2026-25623 | 1 Arista | 1 Edge Threat Management | 2026-06-07 | 6 Medium |
| An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing execution permissions. | ||||
| CVE-2026-25624 | 1 Arista | 1 Edge Threat Management | 2026-06-07 | 5.7 Medium |
| An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls. | ||||
Page 1 of 1.