SSH Session Multiplexing Vulnerability in Arista Networks Products
CVE-2025-54547
5.3MEDIUM
What is CVE-2025-54547?
A vulnerability exists in Arista Networking Devices related to SSH session multiplexing that may allow unauthorized file-system operations to occur after a session timeout has been reached. If configured on the client-side, multiplexed SSH sessions such as SCP or SFTP could exploit this weakness, enabling improper filesystem activities despite the configured session inactivity timeout. This poses a significant risk to the integrity and security of systems relying on proper session management for operations.
Affected Version(s)
DANZ Monitoring Fabric DCA-350E-CV 0
DANZ Monitoring Fabric DCA-350E-CV 0
DANZ Monitoring Fabric DCA-350E-CV 0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
