First published: Mon Oct 26 2020(Updated: )
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista EOS | <4.21.12m | |
Arista EOS | >=4.22<4.22.7m | |
Arista EOS | >=4.23<4.23.5m | |
Arista EOS | >=4.24<4.24.2f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-15897.
The severity of CVE-2020-15897 is high with a CVSS score of 7.5.
Arista EOS versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F are affected by CVE-2020-15897.
CVE-2020-15897 allows remote attackers to cause traffic loss or incorrect forwarding of traffic by sending a malformed link-state PDU to the IS-IS router.
To fix CVE-2020-15897, users should update their Arista EOS software to version 4.21.12M or later, 4.22.7M or later, 4.23.5M or later, or 4.24.2F or later.