7.5
CVE-2023-24513
- EPSS 0.11%
- Published 12.04.2023 20:15:07
- Last modified 21.11.2024 07:48:01
- Source psirt@arista.com
- Teams watchlist Login
- Open Login
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
Data is provided by the National Vulnerability Database (NVD)
Arista ≫ Cloudeos Version >= 4.26.0 < 4.26.9m
Amazon ≫ Aws Marketplace Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Arista ≫ Cloudeos Version >= 4.27.0 < 4.27.8m
Amazon ≫ Aws Marketplace Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Arista ≫ Cloudeos Version >= 4.28.0 < 4.28.5m
Amazon ≫ Aws Marketplace Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Arista ≫ Cloudeos Version >= 4.29.0 < 4.29.2f
Amazon ≫ Aws Marketplace Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Equinix ≫ Network Edge Version-
Google ≫ Google Cloud Platform Marketplace Version-
Microsoft ≫ Azure Marketplace Version-
Arista ≫ Dca-200-veos Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.11% | 0.301 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
psirt@arista.com | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
CWE-126 Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.