8.8
CVE-2024-9188 - Specially constructed queries cause cross platform scripting leaking administrator tokens
Specially constructed queries cause cross platform scripting leaking administrator tokens
7.6
CVE-2024-47520 - A user with advanced report application access rights can perform actions for which they are not auβ¦
A user with advanced report application access rights can perform actions for which they are not authorized
8.3
CVE-2024-47519 - Backup uploads to ETM subject to man-in-the-middle interception
Backup uploads to ETM subject to man-in-the-middle interception
6.4
CVE-2024-47518 - Specially constructed queries targeting ETM could discover active remote access sessions
Specially constructed queries targeting ETM could discover active remote access sessions
6.8
CVE-2024-47517 - Expired and unusable administrator authentication tokens can be revealed by units that have timed oβ¦
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
8.3
CVE-2024-9134 - Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced reβ¦
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
6.6
CVE-2024-9133 - A user with administrator privileges is able to retrieve authentication tokens
A user with administrator privileges is able to retrieve authentication tokens
8.1
CVE-2024-9132 - The administrator is able to configure an insecure captive portal script
The administrator is able to configure an insecure captive portal script
7.2
CVE-2024-9131 - A user with administrator privileges can perform command injection
A user with administrator privileges can perform command injection
4.6
CVE-2024-7142 - On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardwareβ¦
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them