QID 44108

Date Published: 2023-11-07

QID 44108: Arista EOS Kernel Panic Vulnerability (SA0088)

Arista EOS

Arista EOS is a fully programmable and highly modular, Linux-based network operation system, using familiar industry-standard CLI, and runs a single binary software image across the Arista switching family.

Affected EOS versions:
4.28.2F through 4.28.5.1M releases in the 4.28.x train
4.29.1F and below releases in the 4.29.x train
QID Detection Logic (Authenticated):
The check matches Arista EOS version retrieved via Unix Auth using "show version" command. NOTE: Detection is Practice as we are unable to check Required Configuration for Exploitation.

On the affected platforms running EOS, may trigger a kernel panic and cause system reload.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Arista Security Advisory SA0088 for patch details.

    CVEs related to QID 44108

    Software Advisories
    Advisory ID Software Component Link
    security-advisory-0088 URL Logo www.arista.com/en/support/advisories-notices/security-advisory/18042-security-advisory-0088