9.8
CVSSv3

CVE-2020-9015

Published: 20/02/2020 Updated: 11/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow malicious users to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue relating to an overly permissive regular expression in the TACACS+ server permitted commands

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arista dcs-7050qx-32s-r_firmware 4.20.9m

arista dcs-7050cx3-32s-r_firmware 4.20.11m

arista dcs-7280sram-48c6-r_firmware 4.22.0.1f

Exploits

This Metasploit module takes advantage of a poorly configured TACACS+ config, Arista's bash shell, and a TACACS+ read-only account to achieve privilege escalation ...