Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability
CVE-2024-21418
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 March 2024
Summary
The elevation of privilege vulnerability in Software for Open Networking in the Cloud (SONiC) allows an attacker to gain administrative privileges under certain conditions. This flaw could potentially enable unauthorized entities to manipulate network configurations and access sensitive information, leading to severe implications for network integrity and security. Adequate measures should be taken to mitigate this risk to ensure the safe operation of cloud networking environments.
Affected Version(s)
Software for Open Networking in the Cloud (SONiC) Unknown 1.0.0 < 20220531.26
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved