QID 44070
Date Published: 2023-06-27
QID 44070: Arista EOS Improper Handling of Exceptional Conditions Vulnerability (SA0087)
Arista EOS
Arista EOS is a fully programmable and highly modular, Linux-based network operation system, using familiar industry-standard CLI, and runs a single binary software image across the Arista switching family.
Affected EOS versions:
4.29.1F and below releases in the 4.29.x train
4.28.6.1M and below releases in the 4.28.x train
4.27.9M and below releases in the 4.27.x train
4.26.9M and below releases in the 4.26.x train
4.25.10M and below releases in the 4.25.x train
QID Detection Logic (Authenticated):
The check matches Arista EOS version retrieved via Unix Auth using "show version" command.
NOTE: Detection is Practice as we are unable to check Required Configuration for Exploitation.
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
- Arista Security Advisory 0087 -
www.arista.com/en/support/advisories-notices/security-advisory/17445-security-advisory-0087
CVEs related to QID 44070
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Security Advisory 0087 |
|