On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
References
Link | Resource |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisory/17240-security-advisory-0085 | Exploit Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
24 Apr 2023, 16:00
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.arista.com/en/support/advisories-notices/security-advisory/17240-security-advisory-0085 - Exploit, Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-125 | |
CPE | cpe:2.3:a:equinix:network_edge:-:*:*:*:*:*:*:* cpe:2.3:a:amazon:aws_marketplace:-:*:*:*:*:*:*:* cpe:2.3:a:arista:cloudeos:*:*:*:*:*:*:*:* cpe:2.3:a:google:google_cloud_platform_marketplace:-:*:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_marketplace:-:*:*:*:*:*:*:* cpe:2.3:h:arista:dca-200-veos:-:*:*:*:*:*:*:* |
|
First Time |
Arista
Amazon aws Marketplace Equinix Amazon Arista dca-200-veos Microsoft azure Marketplace Microsoft Arista cloudeos Equinix network Edge Google google Cloud Platform Marketplace |
12 Apr 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-12 20:15
Updated : 2023-04-24 16:00
NVD link : CVE-2023-24513
Mitre link : CVE-2023-24513
JSON object : View
Products Affected
arista
- cloudeos
- dca-200-veos
equinix
- network_edge
- google_cloud_platform_marketplace
microsoft
- azure_marketplace
amazon
- aws_marketplace
CWE
CWE-125
Out-of-bounds Read