« Volver al listado

CVE-2024-47517

Estado: AnalizadaMedia (6.8)—

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-47517",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-47517",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-13T20:13:17.296191Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@arista.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@arista.com",
      "affectedData": [
        {
          "vendor": "Arista Networks",
          "product": "Arista Edge Threat Management",
          "versions": [
            {
              "status": "affected",
              "version": "17.1.0",
              "versionType": "custom",
              "lessThanOrEqual": "17.1.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-01-10T22:15:25.923",
  "references": [
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/20454-security-advisory-0105",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "psirt@arista.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@arista.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1230"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access"
    },
    {
      "lang": "es",
      "value": "Los tokens de autenticación de administrador vencidos e inutilizables pueden ser revelados por unidades que han agotado el tiempo de acceso a ETM."
    }
  ],
  "lastModified": "2026-06-17T07:57:13.450",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arista:ng_firewall:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5F6DA5D-4017-40E3-A4E5-6A511F97068A",
              "versionEndIncluding": "17.1.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@arista.com"
}