PT-2020-14696 · Arista · Arista Eos X-Series+1

Published

2020-12-16

·

Updated

2021-01-04

·

CVE-2020-15898

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Arista EOS versions 4.21.4.1F and below releases in the 4.21.x train Arista EOS X-Series versions 4.21.11M and below releases in the 4.21.x train Arista EOS versions 4.22.6M and below releases in the 4.22.x train Arista EOS versions 4.23.4M and below releases in the 4.23.x train Arista EOS versions 4.24.2.1F and below releases in the 4.24.x train
Description The issue allows malformed packets to be incorrectly forwarded across VLAN boundaries in one direction, susceptible to exploitation by unidirectional traffic such as UDP, but not bidirectional traffic like TCP.
Recommendations For Arista EOS versions 4.21.4.1F and below releases in the 4.21.x train, update to a version above 4.21.4.1F. For Arista EOS X-Series versions 4.21.11M and below releases in the 4.21.x train, update to a version above 4.21.11M. For Arista EOS versions 4.22.6M and below releases in the 4.22.x train, update to a version above 4.22.6M. For Arista EOS versions 4.23.4M and below releases in the 4.23.x train, update to a version above 4.23.4M. For Arista EOS versions 4.24.2.1F and below releases in the 4.24.x train, update to a version above 4.24.2.1F.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-15898

Affected Products

Arista Eos
Arista Eos X-Series