5.9

CVE-2020-26569

Exploit

In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.

Data is provided by the National Vulnerability Database (NVD)
AristaEos Version >= 4.21.0f <= 4.21.12m
   Arista7010t-48 Version-
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.22.0f <= 4.22.7m
   Arista7010t-48 Version-
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.23.0f <= 4.23.5m
   Arista7010t-48 Version-
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
AristaEos Version >= 4.24.0f <= 4.24.2f
   Arista7010t-48 Version-
   Arista7050cx3-32s Version-
   Arista7050cx3m-32s Version-
   Arista7050qx-32s Version-
   Arista7050qx2-32s Version-
   Arista7050sx-128 Version-
   Arista7050sx-64 Version-
   Arista7050sx-72q Version-
   Arista7050sx2-128 Version-
   Arista7050sx2-72q Version-
   Arista7050sx3-48c8 Version-
   Arista7050sx3-48yc Version-
   Arista7050sx3-48yc12 Version-
   Arista7050sx3-48yc8 Version-
   Arista7050sx3-96yc8 Version-
   Arista7050tx-48 Version-
   Arista7050tx-64 Version-
   Arista7050tx-72q Version-
   Arista7050tx2-128 Version-
   Arista7050tx3-48c8 Version-
   Arista7060cx-32s Version-
   Arista7060cx2-32s Version-
   Arista7060dx4-32 Version-
   Arista7060px4-32 Version-
   Arista7060sx2-48yc6 Version-
   Arista720xp-24y6 Version-
   Arista720xp-24zy4 Version-
   Arista720xp-48y6 Version-
   Arista720xp-48zc2 Version-
   Arista720xp-96zc2 Version-
   Arista7250qx-64 Version-
   Arista7260cx Version-
   Arista7260cx3 Version-
   Arista7260cx3-64 Version-
   Arista7260qx Version-
   Arista7300x-32q Version-
   Arista7300x-64s Version-
   Arista7300x-64t Version-
   Arista7300x3-32c Version-
   Arista7300x3-48yc4 Version-
   Arista7304x3 Version-
   Arista7308x3 Version-
   Arista7320x-32c Version-
   Arista7324x Version-
   Arista7328x Version-
   Arista7368x4 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.57
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P