CVE-2018-5255: Medium severity arista eos vulnerability
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-5255?
CVE-2018-5255 is a vulnerability in the Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F that allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
How severe is the CVE-2018-5255 vulnerability?
The severity of CVE-2018-5255 is medium, with a severity score of 6.5.
What software is affected by CVE-2018-5255?
The Arista EOS software versions 4.19 before 4.19.4M and 4.20 before 4.20.2F are affected by CVE-2018-5255.
How can the CVE-2018-5255 vulnerability be exploited?
CVE-2018-5255 can be exploited by remote attackers who send crafted UDP packets to the Mlag agent in Arista EOS.
Is there a fix for CVE-2018-5255 vulnerability?
Yes, upgrading to Arista EOS version 4.19.4M or 4.20.2F, or later, fixes the CVE-2018-5255 vulnerability.