First published: Thu Apr 12 2018(Updated: )
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista EOS | <4.20.2f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Arista EOS vulnerability is CVE-2018-5254.
The severity of CVE-2018-5254 is high, with a severity value of 7.5.
The affected software for CVE-2018-5254 is Arista EOS versions up to exclusive 4.20.2F.
Remote BGP peers can exploit CVE-2018-5254 by sending a malformed path attribute in an UPDATE message, causing a denial of service (Rib agent restart).
Yes, Arista has provided a fix for CVE-2018-5254 in Arista EOS version 4.20.2F.