First published: Wed Jan 04 2017(Updated: )
Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista DCS-7050T | <=4.15 | |
Arista DCS-7050T EOS Software | ||
Arista EOS | <=4.15 | |
Arista DCS-7050Q | ||
Arista EOS | <=4.15 | |
Arista DCS-7050S EOS Software |
https://www.arista.com/en/support/advisories-notices/security-advisories/1752-security-advisory-25
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6894 has a denial of service (DoS) impact, allowing remote attackers to reboot affected devices.
To fix CVE-2016-6894, upgrade the affected Arista EOS version to 4.15.8M or later, 4.16.7M or later, or 4.17.0F or later.
CVE-2016-6894 affects DCS-7050 series devices running Arista EOS versions prior to 4.15.8M, 4.16.7M, and 4.17.0F.
CVE-2016-6894 enables a remote denial of service attack that results in the reboot of the device.
No, Arista DCS-7050 devices running versions 4.15.8M, 4.16.7M, or 4.17.0F or later are not vulnerable to CVE-2016-6894.