CVE-2020-24360
Severity CVSS v4.0:
Pending analysis
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
28/12/2020
Last modified:
05/01/2021
Description
An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M and below releases in the 4.23.x train; 4.22.6M and below releases in the 4.22.x train.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Base Score 2.0
6.10
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.22.0f (including) | 4.22.6m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.23.0f (including) | 4.23.4m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.24.0f (including) | 4.24.2.4f (including) |
| cpe:2.3:h:arista:7280cr2ak-30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr2k-60:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3-32d4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3-32p4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3-96:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3k-32d4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3k-32p4:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280cr3k-96:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280dr3-24:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280dr3k-24:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280pr3-24:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7280pr3k-24:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



