On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch.
CVE-2023-24545

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
12 April 2023

What is CVE-2023-24545?

An issue in the Software Forwarding Engine (Sfe) of Arista CloudEOS can lead to potential denial of service attacks. When malformed packets are sent to the switch, it may cause a leak of packet buffers. If a significant number of these packets are received, the switch could cease forwarding legitimate traffic, disrupting network operations and affecting overall system performance.

Affected Version(s)

EOS 4.29.0 <= 4.29.1F

EOS 4.28.0 <= 4.28.4M

EOS 4.27.0 <= 4.27.7M

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.