CVE Vulnerabilities

CVE-2020-11622

Published: Jun 10, 2020 | Modified: Jun 23, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368., 4.21.4-FCRFX., 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1, 4.22.3.1, and 4.23.2.1 Router code in a scenario where TCP MSS options are configured.

Affected Software

Name Vendor Start Version End Version
Cloudeos Arista 4.21.3m (including) 4.21.9m (including)
Cloudeos Arista 4.22.0 (including) 4.22.4m (including)
Cloudeos Arista 4.23.0 (including) 4.23.2m (including)
Cloudeos Arista 4.21.3fx-7368 (including) 4.21.3fx-7368 (including)
Cloudeos Arista 4.21.4-fcrfx (including) 4.21.4-fcrfx (including)
Cloudeos Arista 4.21.4.1 (including) 4.21.4.1 (including)
Cloudeos Arista 4.21.7.1 (including) 4.21.7.1 (including)
Cloudeos Arista 4.22.2.0.1 (including) 4.22.2.0.1 (including)
Cloudeos Arista 4.22.2.2.1 (including) 4.22.2.2.1 (including)
Cloudeos Arista 4.22.3.1 (including) 4.22.3.1 (including)
Cloudeos Arista 4.23.2.1 (including) 4.23.2.1 (including)
Veos Arista 4.21.3m (including) 4.21.9m (including)
Veos Arista 4.22.0 (including) 4.22.4m (including)
Veos Arista 4.23.0 (including) 4.23.2m (including)
Veos Arista 4.21.3fx-7368 (including) 4.21.3fx-7368 (including)
Veos Arista 4.21.4-fcrfx (including) 4.21.4-fcrfx (including)
Veos Arista 4.21.4.1 (including) 4.21.4.1 (including)
Veos Arista 4.21.7.1 (including) 4.21.7.1 (including)
Veos Arista 4.22.2.0.1 (including) 4.22.2.0.1 (including)
Veos Arista 4.22.2.2.1 (including) 4.22.2.2.1 (including)
Veos Arista 4.22.3.1 (including) 4.22.3.1 (including)
Veos Arista 4.23.2.1 (including) 4.23.2.1 (including)

References