CVE-2019-18948
Summary
| CVE | CVE-2019-18948 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-16 19:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Arista | Eos | 4.15 | All | All | All |
| Operating System | Arista | Eos | 4.16 | All | All | All |
| Operating System | Arista | Eos | 4.17 | All | All | All |
| Operating System | Arista | Eos | 4.18 | All | All | All |
| Operating System | Arista | Eos | 4.19 | All | All | All |
| Operating System | Arista | Eos | 4.20 | All | All | All |
| Operating System | Arista | Eos | 4.15 | All | All | All |
| Operating System | Arista | Eos | 4.16 | All | All | All |
| Operating System | Arista | Eos | 4.17 | All | All | All |
| Operating System | Arista | Eos | 4.18 | All | All | All |
| Operating System | Arista | Eos | 4.19 | All | All | All |
| Operating System | Arista | Eos | 4.20 | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
| Operating System | Arista | Eos | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 0047 - Arista | CONFIRM | www.arista.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.