Arista Eos vulnerabilities

44 known vulnerabilities affecting arista/eos.

Total CVEs
44
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH17MEDIUM14LOW4

Vulnerabilities

Page 2 of 3
CVE-2020-25684LOWCVSS 3.7≥ 4.21, < 4.21.14m≥ 4.22, < 4.22.9m+3 more2021-01-20
CVE-2020-25684 [LOW] CWE-358 CVE-2020-25684: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an atta
nvd
CVE-2020-24360HIGHCVSS 7.4≥ 4.22.0f, ≤ 4.22.6m≥ 4.23.0f, ≤ 4.23.4m+1 more2020-12-28
CVE-2020-24360 [HIGH] CWE-404 CVE-2020-24360: An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of product An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M and below releases in the 4.23.x train; 4.22.6M and below releases in the 4.22
nvd
CVE-2020-26569MEDIUMCVSS 5.9≥ 4.21.0f, ≤ 4.21.12m≥ 4.22.0f, ≤ 4.22.7m+2 more2020-12-28
CVE-2020-26569 [MEDIUM] CVE-2020-26569: In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindi In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x
nvd
CVE-2020-15898MEDIUMCVSS 5.3≥ 4.21.0f, ≤ 4.21.4.1f≥ 4.21.0f, ≤ 4.21.11m+3 more2020-12-28
CVE-2020-15898 [MEDIUM] CVE-2020-15898: In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and
nvd
CVE-2020-15897HIGHCVSS 7.5fixed in 4.21.12m≥ 4.22, < 4.22.7m+2 more2020-10-26
CVE-2020-15897 [HIGH] CVE-2020-15897: Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
nvd
CVE-2020-17355HIGHCVSS 7.5≥ 4.21.0, < 4.21.12m≥ 4.22, < 4.22.7m+2 more2020-10-21
CVE-2020-17355 [HIGH] CVE-2020-17355: Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
nvd
CVE-2019-18948HIGHCVSS 7.5≥ 4.21.0, ≤ 4.21.8m≥ 4.22.0, ≤ 4.22.3m+7 more2020-04-16
CVE-2019-18948 [HIGH] CVE-2019-18948: An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases
nvd
CVE-2020-10188CRITICALCVSS 9.8≤ 4.20.15≥ 4.21.0, ≤ 4.21.10m+3 more2020-03-06
CVE-2020-10188 [CRITICAL] CWE-120 CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
nvd
CVE-2015-6815LOWCVSS 3.5v4.12v4.13+2 more2020-01-31
CVE-2015-6815 [LOW] CWE-835 CVE-2015-6815: The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process tran The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
nvd
CVE-2015-5745MEDIUMCVSS 6.5v4.12v4.13+2 more2020-01-23
CVE-2015-5745 [MEDIUM] CWE-120 CVE-2015-5745: Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
nvd
CVE-2015-5278MEDIUMCVSS 6.5v4.12v4.13+2 more2020-01-23
CVE-2015-5278 [MEDIUM] CWE-835 CVE-2015-5278: The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a de The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
nvd
CVE-2015-5239MEDIUMCVSS 6.5v4.12v4.13+2 more2020-01-23
CVE-2015-5239 [MEDIUM] CWE-835 CVE-2015-5239: Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial o Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
nvd
CVE-2019-17596HIGHCVSS 7.5≤ 4.23.1f2019-10-24
CVE-2019-17596 [HIGH] CWE-436 CVE-2019-17596: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic conta Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
nvd
CVE-2018-14008MEDIUMCVSS 6.5≤ 4.21.0f2019-08-15
CVE-2018-14008 [MEDIUM] CWE-287 CVE-2018-14008: Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled. Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
nvd
CVE-2018-5254HIGHCVSS 7.5fixed in 4.20.2f2018-04-12
CVE-2018-5254 [HIGH] CWE-417 CVE-2018-5254: Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) v Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
nvd
CVE-2018-5255MEDIUMCVSS 6.5≥ 4.19, < 4.19.4m≥ 4.20, < 4.20.2f2018-03-05
CVE-2018-5255 [MEDIUM] CVE-2018-5255: The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
nvd
CVE-2017-18017CRITICALCVSS 9.8v4.20.1fx-virtual-router2018-01-03
CVE-2017-18017 [CRITICAL] CWE-416 CVE-2017-18017: The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
nvd
CVE-2017-14491CRITICALCVSS 9.8PoC≤ 4.15≥ 4.16, < 4.16.13m+2 more2017-10-04
CVE-2017-14491 [CRITICAL] CWE-787 CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of servi Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
nvd
CVE-2015-8236CRITICALCVSS 10.0≤ 4.11.11v4.12.5.2+53 more2015-11-19
CVE-2015-8236 [CRITICAL] CWE-264 CVE-2015-8236: Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4. Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.
nvd
CVE-2015-3214MEDIUMCVSS 6.9PoCv4.12v4.13+2 more2015-08-31
CVE-2015-3214 [MEDIUM] CWE-119 CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not dist The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
nvd