Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO
Metrics
Affected Vendors & Products
References
History
Thu, 30 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista danz Monitoring Fabric |
|
| Vendors & Products |
Arista
Arista danz Monitoring Fabric |
Wed, 29 Oct 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO | |
| Title | Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published: 2025-10-29T22:55:54.433Z
Updated: 2025-10-30T14:12:59.838Z
Reserved: 2025-07-24T18:47:24.387Z
Link: CVE-2025-54549
Updated: 2025-10-30T14:12:54.368Z
Status : Awaiting Analysis
Published: 2025-10-29T23:16:19.227
Modified: 2025-10-30T15:03:13.440
Link: CVE-2025-54549
No data.