CVE-2020-15898EOS vulnerability

3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.2%
top 56.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 28
Latest updateMay 24

Description

In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDarista/eos4.21.0f4.21.4.1f+4

🔴Vulnerability Details

2
GHSA
GHSA-63qj-x5v8-6jj4: In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction2022-05-24
CVEList
CVE-2020-15898: In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction2020-12-28
CVE-2020-15898 — Arista EOS vulnerability | cvebase