CVE-2021-28496
- EPSS 0.09%
- Veröffentlicht 21.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 05:59:46
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON ...
CVE-2020-25686
- EPSS 1.21%
- Veröffentlicht 20.01.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:28
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers...
CVE-2020-25685
- EPSS 0.87%
- Veröffentlicht 20.01.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:18:27
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak...
CVE-2020-25684
- EPSS 0.99%
- Veröffentlicht 20.01.2021 16:15:14
- Zuletzt bearbeitet 21.11.2024 05:18:27
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the a...
CVE-2020-24360
- EPSS 0.1%
- Veröffentlicht 28.12.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:39
An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in t...
CVE-2020-15898
- EPSS 0.21%
- Veröffentlicht 28.12.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:06:24
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EO...
CVE-2020-26569
- EPSS 0.39%
- Veröffentlicht 28.12.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:20:06
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. Thi...
CVE-2020-15897
- EPSS 0.69%
- Veröffentlicht 26.10.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:06:24
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
CVE-2020-17355
- EPSS 0.56%
- Veröffentlicht 21.10.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:07:56
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being i...
CVE-2019-18948
- EPSS 0.46%
- Veröffentlicht 16.04.2020 19:15:22
- Zuletzt bearbeitet 21.11.2024 04:33:53
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M an...