CVE-2020-15898

EUVD-2020-7872
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 43%
Affected Products (NVD)
VendorProductVersion
aristaeos
4.21.0f ≤
𝑥
≤ 4.21.4.1f
aristaeos
4.21.0f ≤
𝑥
≤ 4.21.11m
aristaeos
4.22.0f ≤
𝑥
≤ 4.22.6m
aristaeos
4.23.0f ≤
𝑥
≤ 4.23.4m
aristaeos
4.24.0f ≤
𝑥
≤ 4.24.2.1f
𝑥
= Vulnerable software versions