CVE-2024-6437: On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options ma
On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6437?
CVE-2024-6437 is categorized as a medium severity vulnerability.
How do I fix CVE-2024-6437?
To resolve CVE-2024-6437, ensure that your Arista EOS devices are updated to the latest software version provided in the security advisory.
What features are impacted by CVE-2024-6437?
CVE-2024-6437 affects Arista EOS platforms when using features like policy-based routing, BGP Flowspec, or interface traffic policies.
What type of traffic is affected by CVE-2024-6437?
CVE-2024-6437 allows certain IP traffic, such as IPv4 packets with IP options, to bypass configured routing features.
Is there a workaround for CVE-2024-6437?
Currently, no specific workarounds are recommended for CVE-2024-6437 aside from updating the software.