CVE-2023-24509

CRITICAL

Arista EOS 4.23-4.23.13m - Authenticated Privilege Escalation via Standby Supervisor Login

Title source: llm
STIX 2.1

Description

On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.

References (1)

Core 1

Scores

CVSS v3 9.3
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
arista/eos 4.23 - 4.23.13m
Published Apr 13, 2023
Tracked Since Feb 18, 2026