CVE Vulnerabilities

CVE-2020-17355

Published: Oct 21, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.

Affected Software

NameVendorStart VersionEnd Version
EosArista4.21.0 (including)4.21.12m (excluding)
EosArista4.22 (including)4.22.7m (excluding)
EosArista4.23 (including)4.23.5m (excluding)
EosArista4.24.0 (including)4.24.2f (excluding)

References