PT-2020-14696 · Arista · Arista Eos X-Series+1
Published
2020-12-16
·
Updated
2021-01-04
·
CVE-2020-15898
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Arista EOS versions 4.21.4.1F and below releases in the 4.21.x train
Arista EOS X-Series versions 4.21.11M and below releases in the 4.21.x train
Arista EOS versions 4.22.6M and below releases in the 4.22.x train
Arista EOS versions 4.23.4M and below releases in the 4.23.x train
Arista EOS versions 4.24.2.1F and below releases in the 4.24.x train
Description
The issue allows malformed packets to be incorrectly forwarded across VLAN boundaries in one direction, susceptible to exploitation by unidirectional traffic such as UDP, but not bidirectional traffic like TCP.
Recommendations
For Arista EOS versions 4.21.4.1F and below releases in the 4.21.x train, update to a version above 4.21.4.1F.
For Arista EOS X-Series versions 4.21.11M and below releases in the 4.21.x train, update to a version above 4.21.11M.
For Arista EOS versions 4.22.6M and below releases in the 4.22.x train, update to a version above 4.22.6M.
For Arista EOS versions 4.23.4M and below releases in the 4.23.x train, update to a version above 4.23.4M.
For Arista EOS versions 4.24.2.1F and below releases in the 4.24.x train, update to a version above 4.24.2.1F.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arista Eos
Arista Eos X-Series