CVE-2021-28496
- EPSS 0.09%
- Published 21.10.2021 17:15:07
- Last modified 21.11.2024 05:59:46
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON ...
CVE-2020-25686
- EPSS 1.21%
- Published 20.01.2021 17:15:13
- Last modified 21.11.2024 05:18:28
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers...
CVE-2020-25685
- EPSS 0.87%
- Published 20.01.2021 16:15:14
- Last modified 21.11.2024 05:18:27
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak...
CVE-2020-25684
- EPSS 0.99%
- Published 20.01.2021 16:15:14
- Last modified 21.11.2024 05:18:27
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the a...
CVE-2020-24360
- EPSS 0.1%
- Published 28.12.2020 19:15:12
- Last modified 21.11.2024 05:14:39
An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in t...
CVE-2020-15898
- EPSS 0.21%
- Published 28.12.2020 19:15:12
- Last modified 21.11.2024 05:06:24
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EO...
CVE-2020-26569
- EPSS 0.39%
- Published 28.12.2020 16:15:12
- Last modified 21.11.2024 05:20:06
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. Thi...
CVE-2020-15897
- EPSS 0.69%
- Published 26.10.2020 16:15:13
- Last modified 21.11.2024 05:06:24
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
CVE-2020-17355
- EPSS 0.56%
- Published 21.10.2020 22:15:11
- Last modified 21.11.2024 05:07:56
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being i...
CVE-2019-18948
- EPSS 0.46%
- Published 16.04.2020 19:15:22
- Last modified 21.11.2024 04:33:53
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M an...