CVE-2023-24547
Last modified
CVE-2023-24547 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config. . EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arista | Mos | >= 0.13.0, <= 0.39.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-24547?
How severe is CVE-2023-24547?
How do I fix CVE-2023-24547?
Are you affected by CVE-2023-24547?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
