Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
CVE-2024-21418

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 March 2024

Summary

The elevation of privilege vulnerability in Software for Open Networking in the Cloud (SONiC) allows an attacker to gain administrative privileges under certain conditions. This flaw could potentially enable unauthorized entities to manipulate network configurations and access sensitive information, leading to severe implications for network integrity and security. Adequate measures should be taken to mitigate this risk to ensure the safe operation of cloud networking environments.

Affected Version(s)

Software for Open Networking in the Cloud (SONiC) Unknown 1.0.0 < 20220531.26

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.