Vulnerability Description
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arista | Eos | >= 4.21.0, <= 4.21.8m |
References
- https://www.arista.com/en/support/advisories-notices/security-advisories/10292-sPatchVendor Advisory
- https://www.arista.com/en/support/advisories-notices/security-advisories/10292-sPatchVendor Advisory
FAQ
What is CVE-2019-18948?
CVE-2019-18948 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash...
How severe is CVE-2019-18948?
CVE-2019-18948 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18948?
Check the references section above for vendor advisories and patch information. Affected products include: Arista Eos.