First published: Mon Mar 05 2018(Updated: )
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista EOS | >=4.19<4.19.4m | |
Arista EOS | >=4.20<4.20.2f |
https://www.arista.com/en/support/advisories-notices/security-advisories/4347-security-advisory-32
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5255 is a vulnerability in the Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F that allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
The severity of CVE-2018-5255 is medium, with a severity score of 6.5.
The Arista EOS software versions 4.19 before 4.19.4M and 4.20 before 4.20.2F are affected by CVE-2018-5255.
CVE-2018-5255 can be exploited by remote attackers who send crafted UDP packets to the Mlag agent in Arista EOS.
Yes, upgrading to Arista EOS version 4.19.4M or 4.20.2F, or later, fixes the CVE-2018-5255 vulnerability.