CVE-2020-11622

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2020
Last modified:
23/06/2020

Description

A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.21.4-FCRFX.*, 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1, 4.22.3.1, and 4.23.2.1 Router code in a scenario where TCP MSS options are configured.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arista:cloudeos:*:*:*:*:*:*:*:* 4.21.3m (including) 4.21.9m (including)
cpe:2.3:a:arista:cloudeos:*:*:*:*:*:*:*:* 4.22.0 (including) 4.22.4m (including)
cpe:2.3:a:arista:cloudeos:*:*:*:*:*:*:*:* 4.23.0 (including) 4.23.2m (including)
cpe:2.3:a:arista:cloudeos:4.21.3fx-7368:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.21.4-fcrfx:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.21.4.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.21.7.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.22.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.22.2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.22.3.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:cloudeos:4.23.2.1:*:*:*:*:*:*:*
cpe:2.3:a:arista:veos:*:*:*:*:*:*:*:* 4.21.3m (including) 4.21.9m (including)
cpe:2.3:a:arista:veos:*:*:*:*:*:*:*:* 4.22.0 (including) 4.22.4m (including)
cpe:2.3:a:arista:veos:*:*:*:*:*:*:*:* 4.23.0 (including) 4.23.2m (including)
cpe:2.3:a:arista:veos:4.21.3fx-7368:*:*:*:*:*:*:*