CVE-2025-6978
7.2Arista Networks · Arista Edge Threat Management, Arista Next Generation Firewall
A command injection vulnerability in Arista Edge Threat Management allows an authenticated administrator to execute arbitrary OS commands.
Executive summary
A critical command injection vulnerability in Arista Edge Threat Management requires immediate attention to prevent unauthorized OS command execution by authenticated administrators.
Vulnerability
This vulnerability is an OS command injection (CWE-78) flaw present in the diagnostics functionality of the software. It requires an attacker to possess high privileges (authenticated as an administrator) to successfully trigger the injection.
Business impact
Successful exploitation of this flaw allows an attacker with administrative access to execute arbitrary commands on the underlying operating system. This could lead to a full compromise of the firewall appliance, resulting in unauthorized data access, network traffic interception, or total loss of system availability. Given the CVSS score of 7.2, this is a high-severity issue that directly threatens the integrity and security of the network perimeter.
Remediation
Immediate Action: Upgrade Arista Edge Threat Management to version 17.4 or later to apply the necessary security patches.
Proactive Monitoring: Review administrative access logs for anomalous activity or unexpected command executions originating from the diagnostics interface.
Compensating Controls: Restrict administrative access to the management interface to trusted IP addresses only, and ensure that only authorized personnel have elevated credentials.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The vulnerability represents a significant risk to the integrity of the network infrastructure. Administrators should prioritize the upgrade to version 17.4 immediately to remediate the command injection flaw. Maintaining strict access control and monitoring for unauthorized administrative actions remains essential until the patch is successfully applied.
More Arista Networks CVEs
Sources
Originally found and disclosed by Arista would like to acknowledge and thank Gereon Huppertz working with Trend Zero Day Initiative for reporting CVE-2025, per the CVE Program record.