Full Report
Arista Networks security advisory (AV26-940)
Analysis Summary
# Vulnerability: Arista EOS Privilege Escalation via Command Line Interface
## CVE Details
- **CVE ID:** CVE-2024-37381
- **CVSS Score:** 8.8 (High)
- **CWE:** CWE-269 (Improper Privilege Management)
## Affected Systems
- **Products:** Arista Extensible Operating System (EOS)
- **Versions:**
- 4.32.x (prior to 4.32.1F)
- 4.31.x (prior to 4.31.5M)
- 4.30.x (prior to 4.30.9M)
- 4.29.x (prior to 4.29.10M)
- 4.28.x (prior to 4.28.11M)
- **Configurations:** Systems where local or remote user authentication is enabled for CLI access.
## Vulnerability Description
A vulnerability in the Command Line Interface (CLI) of Arista EOS allows an authenticated user to bypass intended command restrictions. By supplying specifically crafted input to certain CLI commands, a user with low-privilege access can execute arbitrary commands with elevated (root) privileges on the underlying operating system.
## Exploitation
- **Status:** Not exploited (No known active exploitation in the wild at time of advisory).
- **Complexity:** Low
- **Attack Vector:** Network (Authenticated CLI session)
## Impact
- **Confidentiality:** High (Full access to system data and configuration)
- **Integrity:** High (Ability to modify system files and firmware)
- **Availability:** High (Potential for complete system denial of service)
## Remediation
### Patches
Arista recommends upgrading to the following remediated versions or higher:
- 4.32.1F
- 4.31.5M
- 4.30.9M
- 4.29.10M
- 4.28.11M
### Workarounds
No specific configuration workaround is available. The primary mitigation is to restrict CLI access to trusted users and implement the principle of least privilege until patches can be applied.
## Detection
- **Indicators of compromise:** Review AAA (Authentication, Authorization, and Accounting) logs for unusual or unauthorized command executions by low-privileged accounts.
- **Detection methods:** Monitor system logs for unexpected shell access (e.g., transitions to `bash` or execution of `sudo` commands not initiated by administrators).
## References
- **Vendor Advisory 0174:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices/security-advisory/24730-security-advisory-0174
- **Arista Security Portal:** hxxps[://]www[.]arista[.]com/en/support/advisories-notices
- **Cyber Centre Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/arista-networks-security-advisory-av26-940