CVE-2020-26569
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/12/2020
Last modified:
27/01/2021
Description
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.21.0f (including) | 4.21.12m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.22.0f (including) | 4.22.7m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.23.0f (including) | 4.23.5m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.24.0f (including) | 4.24.2f (including) |
| cpe:2.3:h:arista:7010t-48:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050cx3-32s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050cx3m-32s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050qx-32s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050qx2-32s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx-128:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx-64:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx-72q:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx2-128:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx2-72q:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:arista:7050sx3-48c8:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



