PT-2018-12273 · Arista · Arista Eos

Publicado

2018-09-13

·

Atualizado

2019-08-28

·

CVE-2018-14008

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Arista EOS versions prior to 4.21.0F
Description The issue arises from the mishandling of 802.1x authentication, which can also affect MACSec when dynamic keys are used. This allows for a denial of service attack at the data plane by crashing the Dot1x agent via a crafted packet sent from the data port, preventing other users from successfully authenticating with the device. There is no evidence of this vulnerability being exploited as of the last update.
Recommendations For Arista EOS versions prior to 4.21.0F, update to a version later than 4.21.0F to resolve the issue. As a temporary workaround, consider restricting access to the 802.1x authentication feature to minimize the risk of exploitation.

Correção

DoS

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14008

Produtos afetados

Arista Eos