VYPR

Arista Edge Threat Management

by Arista Networks

CVEs (9)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2024-91880.000.01Jan 10, 2025Specially constructed queries cause cross platform scripting leaking administrator tokens
CVE-2024-475200.000.00Jan 10, 2025A user with advanced report application access rights can perform actions for which they are not authorized
CVE-2024-475190.000.00Jan 10, 2025Backup uploads to ETM subject to man-in-the-middle interception
CVE-2024-475180.000.00Jan 10, 2025Specially constructed queries targeting ETM could discover active remote access sessions
CVE-2024-475170.000.00Jan 10, 2025Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVE-2024-91340.000.00Jan 10, 2025Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
CVE-2024-91330.000.00Jan 10, 2025A user with administrator privileges is able to retrieve authentication tokens
CVE-2024-91320.000.01Jan 10, 2025The administrator is able to configure an insecure captive portal script
CVE-2024-91310.000.00Jan 10, 2025A user with administrator privileges can perform command injection