CVE-2025-6978 is a diagnostics command injection vulnerability affecting the Arista NG Firewall, allowing for arbitrary code execution. This high-severity vulnerability (CVSS 7.2) can be exploited remotely with high privileges and low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage, indicating a level of awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Arista Networks | Arista Edge Threat Management - Arista Next Generation Firewall | >= 0.0, <= 17.3.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.