Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The recommended resolution for all issues documented above is to upgrade to the version indicated below at your earliest convenience. * 17.2 Upgrade
Vendor Workaround
For the Reports application, for all Reports Users, disable Online Access. To do this: * As the NGFW administrator, log into the UI and go to the Reports application. * For all users with the Online Access checkbox (red box) enabled, uncheck it. * Click Save.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50433 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. |
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista ng Firewall |
|
| CPEs | cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arista
Arista ng Firewall |
Mon, 13 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Jan 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Title | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2025-01-13T20:14:00.556Z
Reserved: 2024-09-23T22:01:04.566Z
Link: CVE-2024-9134
Updated: 2025-01-13T20:13:56.720Z
Status : Analyzed
Published: 2025-01-10T22:15:27.033
Modified: 2025-12-18T15:05:22.270
Link: CVE-2024-9134
No data.
OpenCVE Enrichment
No data.
EUVD