QID 44179
QID 44179: Arista EOS Multiple Security Vulnerabilities (SA0094)
Arista EOS is a fully programmable and highly modular, Linux-based network operation system, using familiar industry-standard CLI, and runs a single binary software image across the Arista switching family.
Affected EOS versions:
4.31.2F and below releases in the 4.31.x train
4.30.5M and below releases in the 4.30.x train
4.29.7M and below releases in the 4.29.x train
4.28.10.1M and below releases in the 4.28.x train
4.27.12M and below releases in the 4.27.x train
4.26.13M and below releases in the 4.26.x train
QID Detection Logic (Authenticated):
The check matches Arista EOS version retrieved via Unix Auth using "show version" command.
Successful exploitation of this vulnerability can allow an attacker the capability to launch DoS attacks against servers or cause an out of memory (OOM) crash. Therefore the unusually slow network performance, unavailability of a particular website or a sudden loss of connectivity across devices on the same network can be used as indicators of the compromise for the vulnerabilities.
- Arista:Security Advisory SA0094 -
www.arista.com/en/support/advisories-notices/security-advisory/19221-security-advisory-0094
CVEs related to QID 44179
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Arista:Security Advisory SA0094 |
|