HIGH · 7.5

CVE-2016-6894

Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets t...

Vulnerability Description

Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
AristaDcs-7050T Eos Software<= 4.15
AristaDcs-7050T-
AristaDcs-7050Q Eos Software<= 4.15
AristaDcs-7050Q-
AristaDcs-7050S Eos Software<= 4.15
AristaDcs-7050S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-6894?

CVE-2016-6894 is a vulnerability with a CVSS score of 7.5 (HIGH). Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets t...

How severe is CVE-2016-6894?

CVE-2016-6894 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-6894?

Check the references section above for vendor advisories and patch information. Affected products include: Arista Dcs-7050T Eos Software, Arista Dcs-7050T, Arista Dcs-7050Q Eos Software, Arista Dcs-7050Q, Arista Dcs-7050S Eos Software.