CVE-2023-24509: On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading t ...
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24509?
The severity of CVE-2023-24509 is critical, with a CVSS score of 7.8.
How does CVE-2023-24509 impact Arista EOS?
CVE-2023-24509 allows an unprivileged user to escalate privileges and login as a root user on affected Arista EOS platforms with redundant supervisor modules and RPR or SSO configured.
Which versions of Arista EOS are affected by CVE-2023-24509?
Arista EOS versions 4.23 to 4.28.4m are affected by CVE-2023-24509.
How can I fix CVE-2023-24509?
To mitigate CVE-2023-24509, upgrade to a fixed version of Arista EOS, such as 4.29 or later.
Where can I find more information about CVE-2023-24509?
More information about CVE-2023-24509 can be found in the Arista Security Advisory 0082 at https://www.arista.com/en/support/advisories-notices/security-advisory/16985-security-advisory-0082.