← Back

CVE-2019-14810

nvd nist
Published: Oct 10, 2019Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially leading to an Out of Memory (OOM) condition that is disruptive to traffic forwarding. Affected EOS versions include: 4.22 release train: 4.22.1F and earlier releases 4.21 release train: 4.21.0F - 4.21.2.3F, 4.21.3F - 4.21.7.1M 4.20 release train: 4.20.14M and earlier releases 4.19 release train: 4.19.12M and earlier releases End of support release trains (4.18 and 4.17)

Affected (7)

1 product
Extensible Operating System
Configuration A
7 vulnerable · 9 platform
Vulnerable SoftwareAffected Versions
Arista
From 4.19 to 4.19.12m
From 4.20 to 4.20.14m
From 4.21.0f to 4.21.2.3f
From 4.21.3f to 4.21.7
Version 4.17
Version 4.18
Version 4.22.1f
Running on/withPlatform Versions
Arista
7020r
All versions
Arista
7280e
All versions
Arista
7280r
All versions
Arista
7280r2
All versions
Arista
7280r3
All versions
Arista
7500e
All versions
Arista
7500r
All versions
Arista
7500r2
All versions
Arista
7500r3
All versions

References (4)

Timeline

No history available yet.