On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch.
CVE-2023-24545
7.5HIGH
What is CVE-2023-24545?
An issue in the Software Forwarding Engine (Sfe) of Arista CloudEOS can lead to potential denial of service attacks. When malformed packets are sent to the switch, it may cause a leak of packet buffers. If a significant number of these packets are received, the switch could cease forwarding legitimate traffic, disrupting network operations and affecting overall system performance.
Affected Version(s)
EOS 4.29.0 <= 4.29.1F
EOS 4.28.0 <= 4.28.4M
EOS 4.27.0 <= 4.27.7M
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
