Arista patches maximum severity vulnerability that is already being exploited

‘Not intended to be remotely accessible’ isn’t the same as ‘not remotely accessible,’ IDC’s Dickson said. “This is a textbook case of internal functionality that was never actually sufficiently walled off from the exposed interface, which is why a single unauthenticated request could reach it.”

Kenney added the internal-only mindset is not only dangerous now, but is going to be increasingly so now that attackers have discovered the weakness.

“What happened here is a familiar failure,” he said. “Someone writes an internal function and assumes the only thing calling it will be another trusted part of the system, so they don’t sanitize the input the way they would on a public endpoint, because the caller is supposed to be you.” But then, he said, at some point, a change leaves the endpoint reachable from outside, and now a stranger is feeding input to a function written to trust whoever called it. “The code never changed. Its exposure did,” he said.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *