CVE-2024-4578

HIGH

Arista Wireless Access Points - Privilege Escalation

Title source: llm
STIX 2.1

Description

This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require high permissions to exploit this vulnerability, but the config password is required to establish the session. The spawned shell is able to obtain root privileges.

Scores

CVSS v3 8.4
EPSS 0.0049
EPSS Percentile 38.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
Arista Networks/Arista Wireless Access Points 13.0.2.x - 13.0.2-28-vv1002
Arista Networks/Arista Wireless Access Points 15.x
Arista Networks/Arista Wireless Access Points 16.x - 16.1.051-vv6
Published Jun 27, 2024
Tracked Since Feb 18, 2026