CVE-2020-26569

EUVD-2020-19114
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
aristaeos
4.21.0f ≤
𝑥
≤ 4.21.12m
aristaeos
4.22.0f ≤
𝑥
≤ 4.22.7m
aristaeos
4.23.0f ≤
𝑥
≤ 4.23.5m
aristaeos
4.24.0f ≤
𝑥
≤ 4.24.2f
𝑥
= Vulnerable software versions