CVE-2025-5088: Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5088?
The severity of CVE-2025-5088 is rated high with a CVSS score of 8.7.
How do I fix CVE-2025-5088?
To fix CVE-2025-5088, upgrade to a remediated version of Arista CloudVision Exchange (CVX) as soon as possible.
What kind of access does CVE-2025-5088 allow an attacker to gain?
CVE-2025-5088 allows an attacker to gain full root access to all servers in the CVX cluster.
What are the requirements for exploiting CVE-2025-5088?
Exploitation of CVE-2025-5088 requires network access to the Redis service on a CVX server and knowledge of the Redis password.
Is authentication required to exploit CVE-2025-5088?
Yes, an authenticated Redis session is required to exploit CVE-2025-5088.