CVE Vulnerabilities

CVE-2020-26569

Published: Dec 28, 2020 | Modified: Jan 27, 2021
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.

Affected Software

Name Vendor Start Version End Version
Eos Arista 4.21.0f (including) 4.21.12m (including)
Eos Arista 4.22.0f (including) 4.22.7m (including)
Eos Arista 4.23.0f (including) 4.23.5m (including)
Eos Arista 4.24.0f (including) 4.24.2f (including)

References