CVE-2024-12832

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Dec 20, 2024
Updated: Jan 3, 2025
CWE ID 89

Summary

CVE-2024-12832 is a SQL injection vulnerability affecting the Arista NG Firewall's ReportEntry class. This issue allows remote attackers, with authentication, to read and write arbitrary files and disclose sensitive information. The root cause is the lack of proper validation of user-supplied data used in SQL queries. An attacker could potentially combine this weakness with other vulnerabilities to execute arbitrary code as the www-data user.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share