On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.
References
Link | Resource |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisory/18644-security-advisory-0090 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
11 Dec 2023, 19:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:arista:7130:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-48g3s:-:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-96s:-:*:*:*:*:*:*:* cpe:2.3:o:arista:mos:*:*:*:*:*:*:*:* cpe:2.3:h:arista:7130-16g3s:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | () https://www.arista.com/en/support/advisories-notices/security-advisory/18644-security-advisory-0090 - Vendor Advisory | |
First Time |
Arista mos
Arista 7130 Arista 7130-96s Arista Arista 7130-16g3s Arista 7130-48g3s |
|
CWE | CWE-319 |
06 Dec 2023, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-06 00:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-24547
Mitre link : CVE-2023-24547
CVE.ORG link : CVE-2023-24547
JSON object : View
Products Affected
arista
- 7130-48g3s
- mos
- 7130
- 7130-16g3s
- 7130-96s
CWE
CWE-319
Cleartext Transmission of Sensitive Information