CVE-2023-24510: On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
Published Jun 5, 2023
·Updated
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
Affected Software
101 affected components
Arista EOS<=4.25.10m
Arista EOS>=4.26.0<4.26.10m
Arista EOS>=4.27.0<4.27.10m
Arista EOS>=4.28.0<4.28.7m
Arista EOS>=4.29.0<4.29.2f
Arista Ceos
Arista CloudEOS
Arista vEOS
Arista 7010t
Arista 7010t-48
Arista 7010tx-48
Arista 7010tx-48-dc
Arista 7020r
Arista 7020sr-24c2
Arista 7020sr-32c2
Arista 7020tr-48
Arista 7020tra-48
Arista 7050cx3-32s
Arista 7050cx3m-32s
Arista 7050qx-32s
Arista 7050qx2-32s
Arista 7050sx-128
Arista 7050sx-64
Arista 7050sx-72q
Arista 7050sx2-128
Arista 7050sx2-72q
Arista 7050sx3-48c8
Arista 7050sx3-48yc
Arista 7050sx3-48yc12
Arista 7050sx3-48yc8
Arista 7050sx3-96yc8
Arista 7050tx-48
Arista 7050tx-64
Arista 7050tx-72q
Arista 7050tx2-128
Arista 7050tx3-48c8
Arista 7060cx-32s
Arista 7060cx2-32s
Arista 7060dx4-32
Arista 7060px4-32
Arista 7060sx2-48yc6
Arista 7130
Arista 7130-16g3s
Arista 7130-48g3s
Arista 7130-96s
Arista 7150s-24
Arista 7150s-52
Arista 7150s-64
Arista 7150sc-24
Arista 7150sc-64
Arista 7160-32cq
Arista 7160-48tc6
Arista 7160-48yc6
Arista 7170-32c
Arista 7170-32cd
Arista 7170-64c
Arista 7170b-64c
Arista 720df-48y
Arista 720dp-24s
Arista 720dp-48s
Arista 720dt-24s
Arista 720dt-48s
Arista 720dt-48y
Arista 720xp-24y6
Arista 720xp-24zy4
Arista 720xp-48y6
Arista 720xp-48zc2
Arista 720xp-96zc2
Arista 722xpm-48y4
Arista 722xpm-48zy8
Arista 7250qx-64
Arista 7260cx
Arista 7260cx3
Arista 7260cx3-64
Arista 7260qx
Arista 7260qx-64
Arista 7260sx2
Arista 7280e
Arista 7280r2
Arista 7280r3
Arista 7300x-32q
Arista 7300x-64s
Arista 7300x-64t
Arista 7300x3-32c
Arista 7300x3-48yc4
Arista 7320x-32c
Arista 7358x4
Arista 7368x4
Arista 7388x5
Arista 750
Arista 7500e
Arista 7500r
Arista 7500r2
Arista 7500r3
Arista 7500r3-24d
Arista 7500r3-24p
Arista 7500r3-36cq
Arista 7500r3k-36cq
Arista 7800r3-36p
Arista 7800r3-48cq
Arista 7800r3k-48cq
Remediation
Information
CVE-2023-24510 has been fixed in the following releases:
- 4.29.2F and later releases in the 4.29.x train
- 4.28.7M and later releases in the 4.28.x train
- 4.27.10M and later releases in the 4.27.x train
- 4.26.10M and later releases in the 4.26.x train
Event History
Jun 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-24510?
CVE-2023-24510 is considered a medium severity vulnerability affecting Arista EOS and may cause a DHCP relay agent restart.
2
What versions of Arista EOS are affected by CVE-2023-24510?
Versions of Arista EOS up to 4.25.10m and between 4.26.0 and 4.26.10m, along with between 4.27.0 and 4.27.10m, and between 4.28.0 and 4.28.7m are affected by CVE-2023-24510.
3
How do I fix CVE-2023-24510?
To mitigate CVE-2023-24510, users should upgrade their Arista EOS to a version that is not vulnerable.
4
What type of attack can exploit CVE-2023-24510?
An attacker can exploit CVE-2023-24510 by sending a malformed DHCP packet, causing the DHCP relay agent to restart.
5
Is CVE-2023-24510 specific to any Arista hardware devices?
CVE-2023-24510 is specifically associated with the Arista EOS software, rather than any specific hardware devices.