5.3

CVE-2020-15898

Exploit

In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AristaEos Version >= 4.21.0f <= 4.21.4.1f
   Arista7170-32c Version-
   Arista7170-32cd Version-
   Arista7170-64c Version-
AristaEos Version >= 4.21.0f <= 4.21.11m
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.22.0f <= 4.22.6m
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.23.0f <= 4.23.4m
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.24.0f <= 4.24.2.1f
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N