跳转到帖子

recommended_posts

发布于
  • Members

security-advisory-0109

Severity
6
CVSS
(AV:A/AC:M/Au:N/C:N/I:C/A:N)
Published
01/14/2025
Created
01/16/2025
Added
01/15/2025
Modified
01/16/2025

Description

On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication during ASU would be impacted with this bug. The issue was discovered internally by Arista. Arista is not aware of any malicious uses of this issue in customer networks.

Solution(s)

  • upgrade-solution-CVE-2024-8000

References

  • https://attackerkb.com/topics/cve-2024-8000
  • CVE - 2024-8000
  • https://www.arista.com//en/support/advisories-notices/security-advisory/21086-security-advisory-0109
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…