CVE-2019-18948
Estado: ModificadaAlta (7.5)—
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.04%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-18948",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-04-16T19:15:22.383",
"references": [
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisories/10292-security-advisory-47",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisories/10292-security-advisory-47",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train."
},
{
"lang": "es",
"value": "Se encontró un problema en Arista EOS. Los paquetes ARP malformados específicos pueden afectar el reenvío de software de los paquetes VxLAN. Este problema se encuentra en el código EOS VxLAN de Arista, que puede permitir a los atacantes bloquear el agente VxlanSwFwd. Esto afecta a EOS 4.21.8M y versiones anteriores en el tren 4.21.x, 4.22.3M y versiones anteriores en el tren 4.22.x, 4.23.1F y versiones anteriores en el tren 4.23.x, y todas las versiones en 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 tren de código"
}
],
"lastModified": "2026-06-17T02:25:37.723",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F8BCF4B-F2AE-4E98-AF4C-3A0663D474CD",
"versionEndIncluding": "4.21.8m",
"versionStartIncluding": "4.21.0"
},
{
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B4B4E99-29DF-46A3-B504-43F09F4D000B",
"versionEndIncluding": "4.22.3m",
"versionStartIncluding": "4.22.0"
},
{
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A82FB6CA-092F-49C1-863D-AA07E6C3F245",
"versionEndIncluding": "4.23.1f",
"versionStartIncluding": "4.23.0"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.15:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8705CF80-DEFC-4425-8E23-D98FFD678157"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.16:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "045E5867-6089-4735-BD48-BBFC12EF27E5"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.17:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D173671D-2339-4998-BA30-E0B0B7B6A967"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.18:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4751406-01B9-4992-9650-4400A9A39DCD"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.19:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42513A2E-1717-4EE7-8AC3-27595F0B2914"
},
{
"criteria": "cpe:2.3:o:arista:eos:4.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71DFC595-50EA-4879-930E-FC68B9BE996B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}