CVE-2023-24512: High severity arista eos vulnerability
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24512?
CVE-2023-24512 has been classified with a high severity due to its potential to allow unauthorized configuration updates.
How do I fix CVE-2023-24512?
To fix CVE-2023-24512, it is recommended to update the Arista EOS software to a secure version beyond the affected ranges.
What impact does CVE-2023-24512 have on Arista EOS devices?
CVE-2023-24512 allows an authorized attacker to update arbitrary configurations on affected Arista EOS devices if the Streaming Telemetry Agent is enabled.
Which Arista EOS versions are affected by CVE-2023-24512?
CVE-2023-24512 affects Arista EOS versions from 4.26.0 to 4.26.10m, 4.27.0 to 4.27.9m, 4.28.0 to 4.28.6m, and 4.29.0 to 4.29.2f.
Who is vulnerable to CVE-2023-24512?
Users running impacted versions of Arista EOS with the Streaming Telemetry Agent enabled are vulnerable to CVE-2023-24512.