CVE-2024-5872: On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5872?
The severity of CVE-2024-5872 is classified as moderate due to the potential for incorrect control plane behavior.
How do I fix CVE-2024-5872?
To fix CVE-2024-5872, apply the latest security updates provided by Arista for the EOS platform.
What systems are affected by CVE-2024-5872?
CVE-2024-5872 affects systems running Arista EOS that improperly handle specially crafted packets.
What impact does CVE-2024-5872 have on network performance?
CVE-2024-5872 may cause routing instability, including route flaps and incorrect multicast routes.
Is there a workaround for CVE-2024-5872?
Currently, there are no known effective workarounds for CVE-2024-5872 apart from applying the recommended patches.