Vulnerability Intelligence Report
CVE-2015-8236
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:4.24%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| arista | eos | 4.12.5.2, 4.12.6.1, 4.12.7.1, 4.12.8, 4.12.8.1, 4.12.9, 4.12.10, 4.13.1.1f, 4.13.2.1f, 4.13.3.1f, 4.13.4.1f, 4.13.5, 4.13.5.1f, 4.13.6, 4.13.7.2m, 4.13.7.3m, 4.13.7m, 4.13.8m, 4.13.9.1m, 4.13.9m, 4.13.10m, 4.13.11m, 4.13.12m, 4.13.13m, 4.14.0f, 4.14.1f, 4.14.2f, 4.14.3.1f, 4.14.3f, 4.14.4.1f, 4.14.4.2f, 4.14.4f, 4.14.5.1f-ssu, 4.14.5f, 4.14.5fx, 4.14.5fx.1, 4.14.5fx.2, 4.14.5fx.3, 4.14.5fx.4, 4.14.6f, 4.14.7.1f, 4.14.7f, 4.14.8.1f, 4.14.8f, 4.14.9, 4.15.0f, 4.15.0fx, 4.15.0fx1, 4.15.0fxa, 4.15.1f, 4.15.1fx-7060qx, 4.15.1fx-7060x, 4.15.1fxb, 4.15.2f |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
4.243%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2015-11-18T00:00:00 |
| Published | 2015-11-19T11:00:00 |
| Patch Date | 2015-11-18 |
| Last Updated | 2024-08-06T08:13:31 |
Community Chatter & Buzz