CVE-2019-18948
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/04/2020
Last modified:
21/07/2021
Description
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.21.0 (including) | 4.21.8m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.22.0 (including) | 4.22.3m (including) |
| cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | 4.23.0 (including) | 4.23.1f (including) |
| cpe:2.3:o:arista:eos:4.15:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arista:eos:4.16:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arista:eos:4.17:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arista:eos:4.18:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arista:eos:4.19:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arista:eos:4.20:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



