An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HArista Eos
OSArista4.24.0 – 4.24.7m4.25.0 – 4.25.34.25.4 – 4.25.4m4.25.5 – 4.25.5.1m4.26.0 – 4.26.2f
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Related vulnerabilities
CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product
GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)
CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product
ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash
CVE-2023-24509CRITICAL9.3PL ✓same product
Arista EOS: privilege escalation na redundantnym module supervisor
CVE-2021-28500CRITICAL9.1PL ✓same product
Arista EOS: nieprawidłowe użycie AAA API umożliwia nieograniczony dostęp lokalnym użytkownikom
CVE-2020-10188CRITICAL9.8PL ✓same product
Buffer overflow w telnetd (netkit) umożliwiający zdalne wykonanie kodu