Full Report
Arista Networks security advisory (AV26-1015)
Analysis Summary
# Vulnerability: Sensitive Information Disclosure in CloudVision CUE
## CVE Details
- **CVE ID:** CVE-2024-47525
- **CVSS Score:** 7.5 (High)
- **CWE:** CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)
## Affected Systems
- **Products:** Arista CloudVision CUE (Cognitive Wi-Fi)
- **Versions:**
- 2024.2.0 and prior
- 2021.2.0 and prior
- 2022.2.0 and prior
- 2022.3.0 and prior
- **Configurations:** Systems using standard authentication/management interfaces where sensitive data may be exposed via specific API or log outputs.
## Vulnerability Description
A vulnerability in the management interface of Arista CloudVision CUE allows an unauthenticated, remote attacker to gain access to sensitive system information. This occurs due to improper access controls on certain internal endpoints, which could leak data that facilitates further targeted attacks against the network infrastructure.
## Exploitation
- **Status:** Not known to be exploited in the wild; no public PoC currently available.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Sensitive configuration or system data exposure)
- **Integrity:** None
- **Availability:** None
## Remediation
### Patches
Arista recommends upgrading to the following remediated versions:
- CloudVision CUE version **2024.2.1** or higher.
- For legacy branches, refer to the specific maintenance releases identified in Advisory 0190.
### Workarounds
- **Access Control Lists (ACLs):** Restrict access to the CloudVision CUE management interface to trusted management networks only.
- **VPN/MGT Isolation:** Ensure the management plane is isolated from general user traffic.
## Detection
- **Indicators of Compromise:** Unusual access patterns to CUE management APIs from unauthorized or external IP addresses.
- **Detection methods and tools:** Monitor web server logs for CloudVision CUE for repetitive unauthorized requests to administrative or metadata endpoints.
## References
- **Vendor Advisory 0190:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24806-security-advisory-0190
- **Arista Networks Advisories:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices
- **Cyber Centre Bulletin:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/arista-networks-security-advisory-av26-1015