CVE-2020-9015: Critical severity Arista Dcs-7050qx-32s-r Firmware vulnerability
DISPUTED Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue relating to an overly permissive regular expression in the TACACS+ server permitted commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the TACACS+ server configuration for permitted commands: replace the overly permissive regular expression that allows bypass of intended TACACS+ shell restrictions via a '|' character.
TACACS+ server permitted commands regular expression permitted commands (regular expression) = exclude the | character / replace overly permissive regular expression
Event History
Frequently Asked Questions
What is CVE-2020-9015?
CVE-2020-9015 is a vulnerability in Arista DCS-7050QX-32S-R, DCS-7050CX3-32S-R, and DCS-7280SRAM-48C6-R devices that allows attackers to bypass TACACS+ shell restrictions.
What is the severity of CVE-2020-9015?
The severity of CVE-2020-9015 is critical with a CVSS score of 9.8.
Which devices are affected by CVE-2020-9015?
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices are affected.
How can an attacker exploit CVE-2020-9015?
Attackers can exploit CVE-2020-9015 by using the | character to bypass intended TACACS+ shell restrictions.
Is there a fix for CVE-2020-9015?
No fix is currently available, however, Arista has provided configuration guidance to mitigate the issue.