CVE-2020-9015 is a critical vulnerability affecting Arista DCS-7050QX-32S-R, DCS-7050CX3-32S-R, and DCS-7280SRAM-48C6-R devices, allowing attackers to bypass TACACS+ shell restrictions using a pipe character. This flaw, stemming from an overly permissive regular expression in the TACACS+ server, carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Metasploit module exists for exploitation, indicating readily available exploit code. Despite this, there is minimal community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.20.9mCPE matchmatch criteria | cpe:2.3:o:arista:dcs-7050qx-32s-r_firmware:4.20.9m:*:*:*:*:*:*:* | ||
4.20.11mCPE matchmatch criteria | cpe:2.3:o:arista:dcs-7050cx3-32s-r_firmware:4.20.11m:*:*:*:*:*:*:* | ||
4.22.0.1fCPE matchmatch criteria | cpe:2.3:o:arista:dcs-7280sram-48c6-r_firmware:4.22.0.1f:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.