CVE Feed

    Dashboard / CVE / CVE-2023-24509

    CVE-2023-24509

    On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.

    Published:Apr 13, 2023
    Last Modified:Feb 7, 2025
    EPS:Apr 13, 2023
    EPSS Score:0.00054
    CVSS Score:9.3

    Affected Products

    Vendor
    Arista
    Product
    704x3
    Vendor
    Arista
    Product
    7304x
    Vendor
    Arista
    Product
    7304x3
    Vendor
    Arista
    Product
    7308x
    Vendor
    Arista
    Product
    7316x
    Vendor
    Arista
    Product
    7324x
    Vendor
    Arista
    Product
    7328x
    Vendor
    Arista
    Product
    7504r
    Vendor
    Arista
    Product
    7504r3
    Vendor
    Arista
    Product
    7508r
    Vendor
    Arista
    Product
    7508r3
    Vendor
    Arista
    Product
    7512r
    Vendor
    Arista
    Product
    7512r3
    Vendor
    Arista
    Product
    7516r
    Vendor
    Arista
    Product
    755x
    Vendor
    Arista
    Product
    758x
    Vendor
    Arista
    Product
    7804r3
    Vendor
    Arista
    Product
    7808r3
    Vendor
    Arista
    Product
    7812r3
    Vendor
    Arista
    Product
    7816r3
    Vendor
    Arista
    Product
    Eos

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High