CVE-2020-15898: Medium severity arista eos vulnerability
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15898?
CVE-2020-15898 is a vulnerability in Arista EOS where malformed packets can be incorrectly forwarded across VLAN boundaries in one direction.
What is the severity of CVE-2020-15898?
The severity of CVE-2020-15898 is medium with a CVSS score of 5.3.
Which Arista platforms are affected by CVE-2020-15898?
EOS 7170 platforms version 4.21.4.1F and below are affected.
Can the vulnerability be exploited with bidirectional traffic?
No, this vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP).
How can I fix CVE-2020-15898?
To fix CVE-2020-15898, upgrade your EOS 7170 platforms to version 4.21.4.1G or later.