QID 44001

Date Published: 2023-03-27

QID 44001: Arista EOS Improper Access Control Vulnerability (SA0074)

Arista EOS

Arista EOS is a fully programmable and highly modular, Linux-based network operation system, using familiar industry-standard CLI, and runs a single binary software image across the Arista switching family.

Affected EOS versions:
4.27.1F and below releases in the 4.27.x train
4.26.3M and below releases in the 4.26.x train
4.25.6M and below releases in the 4.25.x train
QID Detection Logic (Authenticated):
The check matches Arista EOS version retrieved via Unix Auth using "show version" command.

Successful exploitation could lead to Improper Access Control Vulnerability

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Arista Security Advisory SA0074 for patch details.

    CVEs related to QID 44001

    Software Advisories
    Advisory ID Software Component Link
    Security Advisory 0074 URL Logo www.arista.com/en/support/advisories-notices/security-advisory/15268-security-advisory-0074