On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision
References
Link | Resource |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisory/17250-security-advisory-0086 | Exploit Mitigation Vendor Advisory |
https://www.arista.com/en/support/advisories-notices/security-advisory/17250-security-advisory-0086 | Exploit Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
History
21 Nov 2024, 07:48
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://www.arista.com/en/support/advisories-notices/security-advisory/17250-security-advisory-0086 - Exploit, Mitigation, Vendor Advisory |
09 May 2023, 16:02
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.arista.com/en/support/advisories-notices/security-advisory/17250-security-advisory-0086 - Exploit, Mitigation, Vendor Advisory | |
First Time |
Arista 720xp-24zy4
Arista 7260qx Arista 7150s-64 Arista 7808r3 Arista 7170-64c Arista 7050tx-72q Arista 7130-16g3s Arista 7280dr3k-24 Arista 7280cr3-32d4 Arista dcs-7500e-72s-lc Arista 7500r3-24d Arista 7388x5 Arista 7280dr3-24 Arista 7050sx2-72q Arista 7812r3 Arista dcs-7500r-48s2cq-lc Arista 7050sx3-48yc8 Arista 7020sr-24c2 Arista 7050cx3-32s Arista 7150sc-64 Arista 7500r3-36cq Arista 7170-32cd Arista dcs-7500e-48s-lc Arista 7160-48tc6 Arista 7816r3 Arista 7320x-32c Arista 7358x4 Arista 7280cr2k-60 Arista dcs-7500e-12cm-lc Arista 7050qx2-32s Arista Arista ceos-lab Arista 7280cr3-32p4 Arista 7300x3-48yc4 Arista dcs-7500r-36cq-lc Arista 7060cx2-32s Arista cloudeos Arista 7280pr3-24 Arista 7280cr3k-96 Arista 720xp-48y6 Arista 7050sx3-48c8 Arista 7804r3 Arista 7020tr-48 Arista 7050sx2-128 Arista 720xp-24y6 Arista 96lbs Arista 48s6qd Arista 7060cx-32s Arista 7260cx3 Arista 720dp-48s Arista 7050sx-128 Arista 7050qx-32s Arista veos-lab Arista 7260sx2 Arista 7280sr3k-48yc8 Arista 7368x4 Arista 48lbas Arista dcs-7500e-6c2-lc Arista 7060px4-32 Arista 32qd Arista dcs-7010tx-48 Arista 7280pr3k-24 Arista 48ehs Arista 7050sx-72q Arista dcs-7500r-36q-lc Arista 7020sr-32c2 Arista 7050sx-64 Arista 7050sx3-48yc12 Arista 7050sx3-48yc Arista 7280cr3-96 Arista 7300x-64t Arista dcs-7500e-36q-lc Arista 7300x-64s Arista 7050tx2-128 Arista 7260cx Arista eos Arista 7160-48yc6 Arista 7500r3k-36cq Arista 7170-32c Arista 7280cr3k-32d4 Arista 7300x-32q Arista 720dt-24s Arista dcs-7500-12cq-lc Arista 7280e Arista 7050tx3-48c8 Arista 7130-96s Arista 7020tra-48 Arista 7500r3-24p Arista 720df-48y Arista 7280cr3k-32p4 Arista 7150sc-24 Arista 720xp-48zc2 Arista 7150s-52 Arista 7060dx4-32 Arista 7050tx-48 Arista 7300x3-32c Arista 48lbs Arista 7160-32cq Arista 7050tx-64 Arista 720dp-24s Arista 720xp-96zc2 Arista 7250qx-64 Arista 7170b-64c Arista 7010t-48 Arista 7050sx3-96yc8 Arista 7060sx2-48yc6 Arista 7050cx3m-32s Arista 7150s-24 Arista 7280sr3-48yc8 Arista 7130-48g3s Arista 720dt-48s |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CWE | CWE-863 | |
CPE | cpe:2.3:h:arista:7170-32c:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3-32p4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7160-48tc6:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx3-48yc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx3-96yc8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280pr3-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7358x4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7500r3-24p:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7300x3-32c:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7260sx2:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7060cx2-32s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720dp-24s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7010tx-48:-:*:*:*:*:*:*:* cpe:2.3:a:arista:ceos-lab:*:*:*:*:*:*:*:* cpe:2.3:h:arista:7250qx-64:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500e-48s-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7160-32cq:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx-72q:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7060px4-32:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx3-48yc12:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7170-64c:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050qx2-32s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:32qd:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7320x-32c:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280sr3-48yc8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500-12cq-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280sr3k-48yc8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7020sr-24c2:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7300x-32q:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-16g3s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050qx-32s:-:*:*:*:*:*:*:* cpe:2.3:a:arista:cloudeos:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500e-72s-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3-32d4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7170b-64c:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500r-36cq-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7150sc-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050tx-48:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr2k-60:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx-128:-:*:*:*:*:*:*:* cpe:2.3:h:arista:48s6qd:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720xp-96zc2:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720dt-48s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7010t-48:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7170-32cd:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7808r3:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050cx3-32s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7060cx-32s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:48lbs:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3k-32p4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7150s-64:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3k-96:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7060dx4-32:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050tx3-48c8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500e-12cm-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7260cx:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx-64:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7500r3k-36cq:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500r-48s2cq-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720xp-24y6:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7300x-64s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720xp-48y6:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7020tr-48:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-96s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7816r3:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7300x-64t:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx2-128:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7300x3-48yc4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280pr3k-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280dr3-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7020tra-48:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx2-72q:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720dp-48s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7388x5:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7260cx3:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500e-6c2-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7150s-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:48ehs:-:*:*:*:*:*:*:* cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3k-32d4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7150sc-64:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7500r3-36cq:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7804r3:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720df-48y:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280dr3k-24:-:*:*:*:*:*:*:* cpe:2.3:h:arista:96lbs:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7368x4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050tx-64:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-48g3s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050tx-72q:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7160-48yc6:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7500r3-24d:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7150s-52:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280cr3-96:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500r-36q-lc:-:*:*:*:*:*:*:* cpe:2.3:h:arista:48lbas:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720xp-24zy4:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7260qx:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7020sr-32c2:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7812r3:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050cx3m-32s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7060sx2-48yc6:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7280e:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050tx2-128:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx3-48yc8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720xp-48zc2:-:*:*:*:*:*:*:* cpe:2.3:a:arista:veos-lab:-:*:*:*:*:*:*:* cpe:2.3:h:arista:720dt-24s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7050sx3-48c8:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dcs-7500e-36q-lc:-:*:*:*:*:*:*:* |
25 Apr 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-25 21:15
Updated : 2024-11-21 07:48
NVD link : CVE-2023-24512
Mitre link : CVE-2023-24512
CVE.ORG link : CVE-2023-24512
JSON object : View
Products Affected
arista
- 7060sx2-48yc6
- 7260cx
- 7280cr3k-32p4
- 7050sx2-128
- dcs-7500e-72s-lc
- 7280e
- 48ehs
- 7050sx3-48yc12
- 7300x3-48yc4
- 48lbas
- 7280cr3k-96
- 7280cr3-32p4
- 7050qx-32s
- 720xp-48y6
- 7050cx3m-32s
- 7060cx2-32s
- 7010t-48
- 7280dr3k-24
- 7280pr3k-24
- 7020tr-48
- 7170-32cd
- 7170b-64c
- 7280sr3k-48yc8
- 7050sx3-48yc
- dcs-7500e-12cm-lc
- 48s6qd
- 7150sc-64
- 7160-48yc6
- 720dp-48s
- 7300x-64t
- dcs-7500-12cq-lc
- 720xp-48zc2
- 7050sx3-48yc8
- 7050sx-128
- 7280dr3-24
- 7050sx-64
- 7250qx-64
- 7020tra-48
- 7160-32cq
- 48lbs
- 7150s-52
- 7150s-24
- 7060dx4-32
- dcs-7500r-36q-lc
- 7260sx2
- 7050qx2-32s
- 96lbs
- dcs-7500e-36q-lc
- 7130-48g3s
- 7020sr-32c2
- 7050sx2-72q
- 7170-64c
- 720xp-24zy4
- dcs-7500e-48s-lc
- 7816r3
- 7160-48tc6
- 7358x4
- 7812r3
- 7280pr3-24
- 720dp-24s
- 7130-16g3s
- 32qd
- 7050cx3-32s
- 7500r3-24d
- 7020sr-24c2
- 7150s-64
- 7808r3
- 7060cx-32s
- 7050sx3-48c8
- 7050tx-64
- 7050tx-72q
- 7500r3k-36cq
- 7060px4-32
- 7388x5
- 7280sr3-48yc8
- 7368x4
- dcs-7010tx-48
- 7150sc-24
- 7280cr3-32d4
- 7280cr3-96
- 7170-32c
- 7260qx
- 7300x-32q
- 7050tx-48
- 7500r3-24p
- 720df-48y
- 720dt-24s
- veos-lab
- 7500r3-36cq
- eos
- 7300x3-32c
- 720xp-24y6
- 7280cr3k-32d4
- dcs-7500r-36cq-lc
- 720dt-48s
- cloudeos
- 7130-96s
- 7804r3
- 7050tx3-48c8
- 7320x-32c
- 7050sx3-96yc8
- 7050tx2-128
- ceos-lab
- dcs-7500e-6c2-lc
- 7280cr2k-60
- dcs-7500r-48s2cq-lc
- 7050sx-72q
- 720xp-96zc2
- 7300x-64s
- 7260cx3