CVE-2024-21418HighCVSS 7.8

Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

Published
March 12, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What privileges could an attacker gain with a successful exploitation? An unprivileged attacker with read only permissions can escalate to Root in the Border Gateway Protocol container and perform specific actions that enable them to escape the container.

🎯 Affected products4

  • Software for Open Networking in the Cloud (SONiC) 201811
  • Software for Open Networking in the Cloud (SONiC) 201911
  • Software for Open Networking in the Cloud (SONiC) 202012
  • Software for Open Networking in the Cloud (SONiC) 202205

✅ Remediation

KBRelease Notes (Security Update) — fixed build 20220531.26 KBRelease Notes (Security Update) — fixed build 20191130.89 KBRelease Notes (Security Update) — fixed build 20181130.106 KBRelease Notes (Security Update) — fixed build 20201231.96

🔗 References (3)