CVE-2020-26569
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD
Description
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 4.21.0f to 4.21.12m |
| Running on/with | Platform Versions |
|---|---|
Arista 7010t 48 | All versions |
Arista 7050cx3 32s | All versions |
Arista 7050cx3m 32s | All versions |
Arista 7050qx 32s | All versions |
Arista 7050qx2 32s | All versions |
Arista 7050sx 128 | All versions |
Arista 7050sx 64 | All versions |
Arista 7050sx 72q | All versions |
Arista 7050sx2 128 | All versions |
Arista 7050sx2 72q | All versions |
Arista 7050sx3 48c8 | All versions |
Arista 7050sx3 48yc | All versions |
Arista 7050sx3 48yc12 | All versions |
Arista 7050sx3 48yc8 | All versions |
Arista 7050sx3 96yc8 | All versions |
Arista 7050tx 48 | All versions |
Arista 7050tx 64 | All versions |
Arista 7050tx 72q | All versions |
Arista 7050tx2 128 | All versions |
Arista 7050tx3 48c8 | All versions |
Arista 7060cx 32s | All versions |
Arista 7060cx2 32s | All versions |
Arista 7060dx4 32 | All versions |
Arista 7060px4 32 | All versions |
Arista 7060sx2 48yc6 | All versions |
Arista 720xp 24y6 | All versions |
Arista 720xp 24zy4 | All versions |
Arista 720xp 48y6 | All versions |
Arista 720xp 48zc2 | All versions |
Arista 720xp 96zc2 | All versions |
Arista 7250qx 64 | All versions |
Arista 7260cx | All versions |
Arista 7260cx3 | All versions |
Arista 7260cx3 64 | All versions |
Arista 7260qx | All versions |
Arista 7300x 32q | All versions |
Arista 7300x 64s | All versions |
Arista 7300x 64t | All versions |
Arista 7300x3 32c | All versions |
Arista 7300x3 48yc4 | All versions |
Arista 7304x3 | All versions |
Arista 7308x3 | All versions |
Arista 7320x 32c | All versions |
Arista 7324x | All versions |
Arista 7328x | All versions |
Arista 7368x4 | All versions |
References (2)
Source: cve@mitre.org
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Timeline
No history available yet.