TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Bishop Fox

Arista NextGen Firewall XSS to RCE Chain

2025-12-04 · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
97%
"##d and is still exploitable in the latest available software. be sure to upgrade your arista firewalls immediately and / or disable the captive portal to reduce the likelihood of exploitation. keep an eye on this blog for more information coming soon about the undisclosed vulner…"
T1190Exploit Public-Facing Application
73%
"user interaction is required. our researchers found that it is actually a reflected cross - site scripting ( xss ) vulnerability that allows arbitrary content to be injected into a page displayed by the server : the severity of an xss vulnerability depends entirely on its potenti…"

Summary

Arista flagged three NG Firewall bugs as “limited.” Our researchers proved otherwise: real-world remote code execution is possible, and current patches don’t fully fix the root issues. Here’s what’s vulnerable, what we validated, and the steps to cut exposure now.