CVE-2024-12832
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Dec 20, 2024
Updated: Jan 3, 2025
CWE ID 89
Summary
CVE-2024-12832 is a SQL injection vulnerability affecting the Arista NG Firewall's ReportEntry class. This issue allows remote attackers, with authentication, to read and write arbitrary files and disclose sensitive information. The root cause is the lack of proper validation of user-supplied data used in SQL queries. An attacker could potentially combine this weakness with other vulnerabilities to execute arbitrary code as the www-data user.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- NG Firewall
Affected Vendors
- Arista