CVE Vulnerabilities

CVE-2020-17355

Published: Oct 21, 2020 | Modified: Nov 02, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.

Affected Software

Name Vendor Start Version End Version
Eos Arista 4.21.0 (including) 4.21.12m (excluding)
Eos Arista 4.22 (including) 4.22.7m (excluding)
Eos Arista 4.23 (including) 4.23.5m (excluding)
Eos Arista 4.24.0 (including) 4.24.2f (excluding)

References