CVE-2020-26569: Medium severity arista eos vulnerability
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26569?
CVE-2020-26569 is a vulnerability in EVPN VxLAN setups in Arista EOS where specific malformed packets can lead to incorrect MAC to IP bindings.
Which versions of Arista EOS are affected by CVE-2020-26569?
Arista EOS versions 4.21.12M and below releases in 4.21 series, 4.22.7M and below releases in 4.22 series, 4.23.5M and below releases in 4.23 series, and 4.24.2F and below releases in 4.24 series are affected by CVE-2020-26569.
What is the severity of CVE-2020-26569?
The severity of CVE-2020-26569 is medium with a CVSS score of 5.9.
How can CVE-2020-26569 be exploited?
CVE-2020-26569 can be exploited by sending specific malformed packets in EVPN VxLAN setups in Arista EOS.
How can I fix CVE-2020-26569?
To fix CVE-2020-26569, it is recommended to upgrade to a fixed version of Arista EOS mentioned in the security advisory.