CVE-2018-5254: High severity arista eos vulnerability
Published Apr 12, 2018
·Updated
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
Affected Software
1 affected component
Arista EOS<4.20.2f
Event History
Apr 12, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Arista EOS vulnerability?
The vulnerability ID for this Arista EOS vulnerability is CVE-2018-5254.
2
What is the severity of CVE-2018-5254?
The severity of CVE-2018-5254 is high, with a severity value of 7.5.
3
What is the affected software for CVE-2018-5254?
The affected software for CVE-2018-5254 is Arista EOS versions up to exclusive 4.20.2F.
4
How can remote BGP peers exploit CVE-2018-5254?
Remote BGP peers can exploit CVE-2018-5254 by sending a malformed path attribute in an UPDATE message, causing a denial of service (Rib agent restart).
5
Is there a solution or fix available for CVE-2018-5254?
Yes, Arista has provided a fix for CVE-2018-5254 in Arista EOS version 4.20.2F.