SB2023121484 - Privilege escalation in Arista EOS



SB2023121484 - Privilege escalation in Arista EOS

Published: December 14, 2023 Updated: May 17, 2025

Security Bulletin ID SB2023121484
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper privilege management (CVE-ID: CVE-2023-24509)

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management. On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation.


Remediation

Install update from vendor's website.