PT-2021-3540 · Arista+6 · Arista Eos+6

Published

2021-01-19

·

Updated

2024-06-15

·

CVE-2020-25684

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Dnsmasq (affected versions not specified) Arista EOS software (affected versions not specified)
Description The issue is related to errors in the implementation of security checks for standard elements in the Dnsmasq DNS server's reply query() function. This can be exploited by a remote attacker to compromise the integrity of protected information. Additionally, various issues with Dnsmasq may result in the DNS cache being poisoned by a malicious attacker, causing other clients querying the EOS switch as a DNS server to receive invalid DNS records. This issue requires a specific configuration to be set in EOS to allow using the EOS switch as a DNS server.
Recommendations For Dnsmasq, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Arista EOS software, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1126
ALT-PU-2021-1167
ALT-PU-2021-1217
BDU:2021-03624
CESA-2021_0150
CESA-2021_0153
CVE-2020-25684
DLA-2604-1
DSA-4844-1
MGASA-2021-0059
OESA-2021-1001
OPENSUSE-SU-2021:0124-1
OPENSUSE-SU-2021:0129-1
OPENSUSE-SU-2021_0124-1
OPENSUSE-SU-2021_0129-1
OPENSUSE-SU-2024:10721-1
RHSA-2021:0150
RHSA-2021:0151
RHSA-2021:0152
RHSA-2021:0153
RHSA-2021:0154
RHSA-2021:0155
RHSA-2021:0156
RHSA-2021:0240
RHSA-2021:0245
RHSA-2021:0395
RHSA-2021:0401
RHSA-2021_0150
RHSA-2021_0153
SUSE-SU-2021:0162-1
SUSE-SU-2021:0163-1
SUSE-SU-2021:0166-1
SUSE-SU-2021:14603-1
SUSE-SU-2021:14604-1
SUSE-SU-2021_14603-1
USN-4698-1
USN-4698-2

Affected Products

Alt Linux
Arista Eos
Centos
Linuxmint
Red Hat
Suse
Ubuntu