CVE-2024-913110.01.2025, 22:15A user with administrator privileges can perform command injectionArgument InjectionEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.2 HIGHNETWORKLOWHIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HAristaCNA7.2 HIGHNETWORKLOWHIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HCISA-ADPADP------Awaiting analysisThis vulnerability is currently awaiting analysis.Base ScoreCVSS 3.xEPSS ScorePercentile: 40%Common Weakness EnumerationCWE-88 - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.Referenceshttps://www.arista.com/en/support/advisories-notices/security-advisory/20454-security-advisory-0105