CVE-2023-24509
Summary
| CVE | CVE-2023-24509 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-13 20:15:00 UTC |
| Updated | 2023-04-25 14:19:00 UTC |
| Description | On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Arista | 704x3 | - | All | All | All |
| Hardware | Arista | 7304x | - | All | All | All |
| Hardware | Arista | 7304x3 | - | All | All | All |
| Hardware | Arista | 7308x | - | All | All | All |
| Hardware | Arista | 7316x | - | All | All | All |
| Hardware | Arista | 7324x | - | All | All | All |
| Hardware | Arista | 7328x | - | All | All | All |
| Hardware | Arista | 7504r | - | All | All | All |
| Hardware | Arista | 7504r3 | - | All | All | All |
| Hardware | Arista | 7508r | - | All | All | All |
| Hardware | Arista | 7508r3 | - | All | All | All |
| Hardware | Arista | 7512r | - | All | All | All |
| Hardware | Arista | 7512r3 | - | All | All | All |
| Hardware | Arista | 7516r | - | All | All | All |
| Hardware | Arista | 755x | - | All | All | All |
| Hardware | Arista | 758x | - | All | All | All |
| Hardware | Arista | 7804r3 | - | All | All | All |
| Hardware | Arista | 7808r3 | - | All | All | All |
| Hardware | Arista | 7812r3 | - | All | All | All |
| Hardware | Arista | 7816r3 | - | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 0082 - Arista | MISC | www.arista.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Arista would like to acknowledge and thank Marc-André Labonté, Senior Information Security Analyst at Desjardins for responsibly reporting CVE-2023-24509.
Legacy QID Mappings
- 43996 Arista EOS Improper Privilege Management Vulnerability (SA0082)