CVE-2026-25624: Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting
An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25624?
The severity of CVE-2026-25624 is classified as medium with a score of 5.7.
What is CVE-2026-25624?
CVE-2026-25624 is an administrative cross-site scripting (XSS) vulnerability affecting the web user interface of Arista Edge Threat Management NGFW.
How do I fix CVE-2026-25624?
To fix CVE-2026-25624, it is recommended to upgrade to NGFW Version 17.4.1 as soon as possible.
What impact does CVE-2026-25624 have on security?
CVE-2026-25624 can lead to unauthorized access and manipulation of administrative profiles through XSS attacks.
Who is affected by CVE-2026-25624?
Organizations using Arista Edge Threat Management NGFW with unpatched versions are at risk from CVE-2026-25624.