7.5

CVE-2019-18948

An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arista ≫ Eos Version >= 4.21.0 <= 4.21.8m
Arista ≫ Eos Version >= 4.22.0 <= 4.22.3m
Arista ≫ Eos Version >= 4.23.0 <= 4.23.1f
Arista ≫ Eos Version 4.15
Arista ≫ Eos Version 4.16
Arista ≫ Eos Version 4.17
Arista ≫ Eos Version 4.18
Arista ≫ Eos Version 4.19
Arista ≫ Eos Version 4.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.596
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.arista.com/en/support/advisories-notices/security-advisories/10292-security-advisory-47
Patch
Vendor Advisory