CVE Vulnerabilities

CVE-2023-24513

Buffer Over-read

Published: Apr 12, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.

Weakness

The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Affected Software

Name Vendor Start Version End Version
Cloudeos Arista 4.26.0 (including) 4.26.9m (excluding)
Cloudeos Arista 4.27.0 (including) 4.27.8m (excluding)
Cloudeos Arista 4.28.0 (including) 4.28.5m (excluding)
Cloudeos Arista 4.29.0 (including) 4.29.2f (excluding)

References