CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-24509

CVSS 9.3v3.1pub. 2023-04-13upd. 2024-11-21

On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Arista 704x3

    HW
    Arista
    all versions
  • Arista 7304x

    HW
    Arista
    all versions
  • Arista 7304x3

    HW
    Arista
    all versions
  • Arista 7308x

    HW
    Arista
    all versions
  • Arista 7316x

    HW
    Arista
    all versions
  • Arista 7324x

    HW
    Arista
    all versions
  • Arista 7328x

    HW
    Arista
    all versions
  • Arista 7504r

    HW
    Arista
    all versions
  • Arista 7504r3

    HW
    Arista
    all versions
  • Arista 7508r

    HW
    Arista
    all versions
  • Arista 7508r3

    HW
    Arista
    all versions
  • Arista 7512r

    HW
    Arista
    all versions
  • Arista 7512r3

    HW
    Arista
    all versions
  • Arista 7516r

    HW
    Arista
    all versions
  • Arista 755x

    HW
    Arista
    all versions
  • Arista 758x

    HW
    Arista
    all versions
  • Arista 7804r3

    HW
    Arista
    all versions
  • Arista 7808r3

    HW
    Arista
    all versions
  • Arista 7812r3

    HW
    Arista
    all versions
  • Arista 7816r3

    HW
    Arista
    all versions
  • Arista Eos

    OS
    Arista
    4.28.0 – 4.28.4m (excl.)4.27.0 – 4.27.7m (excl.)4.26.0 – 4.26.9m (excl.)4.25.0 – 4.25.10m (excl.)4.24.0 – 4.24.11m (excl.)4.23 – 4.23.13m
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2014-7169CRITICAL9.8⚠ KEVPL ✓same product

GNU Bash — niekompletna łatka Shellshock umożliwia command injection (CVE-2014-7169)

CVE-2014-6271CRITICAL9.8⚠ KEVPL ✓same product

ShellShock — RCE poprzez zmienne środowiskowe w GNU Bash

CVE-2021-28506CRITICAL9.1PL ✓same product

Arista EOS: pominięcie autoryzacji w gNOI API umożliwia reset urządzenia

CVE-2021-28500CRITICAL9.1PL ✓same product

Arista EOS: nieprawidłowe użycie AAA API umożliwia nieograniczony dostęp lokalnym użytkownikom

CVE-2020-10188CRITICAL9.8PL ✓same product

Buffer overflow w telnetd (netkit) umożliwiający zdalne wykonanie kodu