CVE-2024-12831

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Dec 20, 2024
Updated: Jan 3, 2025
CWE ID 863

Summary

CVE-2024-12831 is a newly disclosed vulnerability in the Arista NG Firewall's uvm_login module. This issue grants local attackers the ability to escalate privileges, providing them with unrestricted access to resources that should be protected. To exploit this vulnerability, an attacker must first gain the capacity to execute low-privileged code on the targeted system. The underlying cause of this flaw is incorrect authorization handling within the module. This vulnerability, originally identified as ZDI-CAN-24324, poses a significant risk to affected installations of Arista NG Firewall.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share