CVE-2023-24547
On Arista MOS configuration of a BGP password will cause the password to be logged in clear text.
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.
En las plataformas afectadas que ejecutan Arista MOS, la configuración de una contraseña BGP hará que la contraseña se registre en texto plano que los usuarios autenticados pueden revelar en registros locales o servidores de registro remotos, además de aparecer en texto plano en la configuración en ejecución del dispositivo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-01-26 CVE Reserved
- 2023-12-05 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
- CAPEC-122: Privilege Abuse
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arista Search vendor "Arista" | Mos Search vendor "Arista" for product "Mos" | >= 0.13.0 <= 0.39.4 Search vendor "Arista" for product "Mos" and version " >= 0.13.0 <= 0.39.4" | - |
Affected
| in | Arista Search vendor "Arista" | 7130 Search vendor "Arista" for product "7130" | - | - |
Safe
|
Arista Search vendor "Arista" | Mos Search vendor "Arista" for product "Mos" | >= 0.13.0 <= 0.39.4 Search vendor "Arista" for product "Mos" and version " >= 0.13.0 <= 0.39.4" | - |
Affected
| in | Arista Search vendor "Arista" | 7130-16g3s Search vendor "Arista" for product "7130-16g3s" | - | - |
Safe
|
Arista Search vendor "Arista" | Mos Search vendor "Arista" for product "Mos" | >= 0.13.0 <= 0.39.4 Search vendor "Arista" for product "Mos" and version " >= 0.13.0 <= 0.39.4" | - |
Affected
| in | Arista Search vendor "Arista" | 7130-48g3s Search vendor "Arista" for product "7130-48g3s" | - | - |
Safe
|
Arista Search vendor "Arista" | Mos Search vendor "Arista" for product "Mos" | >= 0.13.0 <= 0.39.4 Search vendor "Arista" for product "Mos" and version " >= 0.13.0 <= 0.39.4" | - |
Affected
| in | Arista Search vendor "Arista" | 7130-96s Search vendor "Arista" for product "7130-96s" | - | - |
Safe
|