CVE-2020-17355: High severity arista eos vulnerability
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-17355.
What is the affected software?
The affected software is Arista EOS versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F.
What is the severity of CVE-2020-17355?
The severity of CVE-2020-17355 is high, with a severity score of 7.5.
How does CVE-2020-17355 impact the system?
CVE-2020-17355 allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
How can I fix CVE-2020-17355?
To fix CVE-2020-17355, it is recommended to update to Arista EOS versions 4.21.12M, 4.22.7M, 4.23.5M, or 4.24.2F, which contain the necessary security patches.