Arista Firewall XSS to RCE Chain
ResearchNext Generation Firewall (NGFW) Read at Bishop Fox
Below is the opening; the full story is at Bishop Fox.
From Bishop Fox
Summary
Last week*, Arista disclosed that its Next Generation Firewall (NGFW) appliances are affected by three high-severity vulnerabilities: sensitive information disclosure (CVE-2025-6980), authentication bypass (CVE-2025-6979), and command injection (CVE-2025-6978). The vendor released a patch (software version 17.4) to address these issues.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.