QID 44109
Date Published: 2023-10-23
QID 44109: Arista EOS Buffer Copy Without Checking Size of Input Vulnerability (SA0089)
Arista EOS
Arista EOS is a fully programmable and highly modular, Linux-based network operation system, using familiar industry-standard CLI, and runs a single binary software image across the Arista switching family.
Affected EOS versions:
4.25.0F in the 4.25.x train
4.24.11M and below releases in the 4.24.x train
4.23.14M and below releases in the 4.23.x train
4.22.13M and below releases till 4.22.1F in the 4.22.x train
QID Detection Logic (Authenticated):
The check matches Arista EOS version retrieved via Unix Auth using "show version" command.
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets.
- Arista:Security Advisory 0089 -
www.arista.com/en/support/advisories-notices/security-advisory/18043-security-advisory-0089
CVEs related to QID 44109
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| security-advisory-0089 |
|