CVE-2024-12378: On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12378?
CVE-2024-12378 is considered a high severity vulnerability due to the exposure of sensitive data over secure Vxlan tunnels.
How do I fix CVE-2024-12378?
To mitigate CVE-2024-12378, ensure that the Tunnelsec agent is not restarted unnecessarily on Arista EOS systems.
What are the consequences of CVE-2024-12378?
The consequence of CVE-2024-12378 is that sensitive packets may be sent unencrypted over a secure Vxlan tunnel, risking data exposure.
Which systems are affected by CVE-2024-12378?
CVE-2024-12378 affects platforms running Arista EOS with secure Vxlan configurations.
What is the impact of CVE-2024-12378 on network security?
The impact of CVE-2024-12378 on network security is significant as it can lead to unauthorized data interception and compromise of secure communications.