« Volver al listado

CVE-2019-18948

Estado: ModificadaAlta (7.5)—

An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-18948",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-04-16T19:15:22.383",
  "references": [
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisories/10292-security-advisory-47",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisories/10292-security-advisory-47",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train."
    },
    {
      "lang": "es",
      "value": "Se encontró un problema en Arista EOS. Los paquetes ARP malformados específicos pueden afectar el reenvío de software de los paquetes VxLAN. Este problema se encuentra en el código EOS VxLAN de Arista, que puede permitir a los atacantes bloquear el agente VxlanSwFwd. Esto afecta a EOS 4.21.8M y versiones  anteriores  en el tren 4.21.x, 4.22.3M y versiones anteriores  en el tren 4.22.x, 4.23.1F y versiones anteriores  en el tren 4.23.x, y todas las versiones en 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 tren de código"
    }
  ],
  "lastModified": "2026-06-17T02:25:37.723",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F8BCF4B-F2AE-4E98-AF4C-3A0663D474CD",
              "versionEndIncluding": "4.21.8m",
              "versionStartIncluding": "4.21.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B4B4E99-29DF-46A3-B504-43F09F4D000B",
              "versionEndIncluding": "4.22.3m",
              "versionStartIncluding": "4.22.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A82FB6CA-092F-49C1-863D-AA07E6C3F245",
              "versionEndIncluding": "4.23.1f",
              "versionStartIncluding": "4.23.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.15:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8705CF80-DEFC-4425-8E23-D98FFD678157"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "045E5867-6089-4735-BD48-BBFC12EF27E5"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D173671D-2339-4998-BA30-E0B0B7B6A967"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B4751406-01B9-4992-9650-4400A9A39DCD"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "42513A2E-1717-4EE7-8AC3-27595F0B2914"
            },
            {
              "criteria": "cpe:2.3:o:arista:eos:4.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71DFC595-50EA-4879-930E-FC68B9BE996B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}