First published: Mon Oct 26 2020(Updated: )
Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista Cloudvision Exchange | >=4.21.5f<4.21.12m | |
Arista Cloudvision Exchange | >=4.22.0<4.22.7m | |
Arista Cloudvision Exchange | >=4.23.0<4.23.5m | |
Arista Cloudvision Exchange | >=4.24.0<4.24.2f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13100 is a vulnerability in Arista’s CloudVision eXchange (CVX) server that allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.
Arista’s CloudVision eXchange (CVX) server versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F are affected by CVE-2020-13100.
CVE-2020-13100 has a severity rating of 7.5 (high).
To fix CVE-2020-13100, you should update Arista’s CloudVision eXchange (CVX) server to version 4.21.12M, 4.22.7M, 4.23.5M, or 4.24.2F or later.
You can find more information about CVE-2020-13100 at the following link: [https://www.arista.com/en/support/advisories-notices/security-advisories/11758-security-advisory-52](https://www.arista.com/en/support/advisories-notices/security-advisories/11758-security-advisory-52)