CVE-2015-8236: Critical severity arista eos vulnerability
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8236?
CVE-2015-8236 has a high severity, allowing remote attackers to execute arbitrary code as root.
How do I fix CVE-2015-8236?
To fix CVE-2015-8236, upgrade to Arista EOS versions 4.11.12 or later, 4.12.11 or later, 4.13.14M or later, 4.14.5FX.5 or later, or 4.15.0FX1.1 or later.
What versions of Arista EOS are affected by CVE-2015-8236?
CVE-2015-8236 affects versions of Arista EOS prior to 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1.
Can CVE-2015-8236 be exploited remotely?
Yes, CVE-2015-8236 can be exploited remotely due to compromised management-plane access.
What are the potential impacts of CVE-2015-8236?
Exploitation of CVE-2015-8236 may lead to unauthorized root access and potential full system compromise.