Packet Handling Vulnerability in Arista EOS Affects Network Control
CVE-2024-5872

Currently unrated

Key Information:

Vendor
CVE Published:
10 January 2025

What is CVE-2024-5872?

A vulnerability in Arista EOS has been identified, where specially crafted packets with incorrect VLAN tags may inadvertently be processed by the CPU. This can lead to erratic behavior in the control plane, manifesting as route flaps and unexpected multicast route behaviors. Such disruptions could impact network stability and performance, making it essential for users of Arista EOS to assess their systems and implement recommended mitigations to maintain operational integrity.

References

Timeline

  • Vulnerability published

.