CVE-2023-24547 is a medium-severity vulnerability affecting Arista MOS on various 7130 series platforms, where BGP passwords are logged and displayed in cleartext within local logs, remote logging servers, and the device's running configuration. This flaw, rated 6.5 CVSS, allows authenticated users to access sensitive BGP passwords due to improper handling of sensitive information (CWE-319). While the attack vector is network-based with low complexity and requires authenticated access, it poses a high risk of confidentiality compromise. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.13.0, <= 0.39.4CPE matchmatch criteria | cpe:2.3:o:arista:mos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.