First published: Wed Oct 21 2020(Updated: )
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arista EOS | >=4.21.0<4.21.12m | |
Arista EOS | >=4.22<4.22.7m | |
Arista EOS | >=4.23<4.23.5m | |
Arista EOS | >=4.24.0<4.24.2f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-17355.
The affected software is Arista EOS versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F.
The severity of CVE-2020-17355 is high, with a severity score of 7.5.
CVE-2020-17355 allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
To fix CVE-2020-17355, it is recommended to update to Arista EOS versions 4.21.12M, 4.22.7M, 4.23.5M, or 4.24.2F, which contain the necessary security patches.