CVE-2019-14810: Race Condition
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially leading to an Out of Memory (OOM) condition that is disruptive to traffic forwarding. Affected EOS versions include: 4.22 release train: 4.22.1F and earlier releases 4.21 release train: 4.21.0F - 4.21.2.3F, 4.21.3F - 4.21.7.1M 4.20 release train: 4.20.14M and earlier releases 4.19 release train: 4.19.12M and earlier releases End of support release trains (4.18 and 4.17)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-14810.
What is the affected software?
The affected software is Arista Extensible Operating System (EOS).
What is the severity of CVE-2019-14810?
The severity of CVE-2019-14810 is medium with a CVSS score of 5.9.
What is the risk of CVE-2019-14810?
CVE-2019-14810 poses a risk of Denial of Service (DoS) attack on route updates in the affected software.
How can I fix CVE-2019-14810?
To fix CVE-2019-14810, it is recommended to update to a patched version of Arista Extensible Operating System (EOS) as mentioned in the Arista advisory.