PT-2018-16843 · Arista · Arista Eos

Published

2018-03-01

·

Updated

2019-10-03

·

CVE-2018-5255

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Arista EOS versions 4.19 through 4.19.4M Arista EOS versions 4.20 through 4.20.2F
Description The issue allows remote attackers to cause a denial of service, specifically an agent restart, by sending crafted UDP packets to the switch's IP address on a specific UDP port. These malformed UDP packets are not typically expected in production environments and would need to be crafted and sent by a malicious user.
Recommendations For Arista EOS versions 4.19 through 4.19.4M, update to version 4.19.4M or later. For Arista EOS versions 4.20 through 4.20.2F, update to version 4.20.2F or later. As a temporary workaround, consider restricting access to the specific UDP port used by the Mlag agent to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-5255

Affected Products

Arista Eos