« Volver al listado

CVE-2023-24545

Estado: ModificadaAlta (7.5)—

On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-24545",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-24545",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-07T15:50:36.827968Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@arista.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@arista.com",
      "affectedData": [
        {
          "vendor": "Arista Networks",
          "product": "EOS",
          "versions": [
            {
              "status": "affected",
              "version": "4.29.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.29.1F"
            },
            {
              "status": "affected",
              "version": "4.28.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.28.4M"
            },
            {
              "status": "affected",
              "version": "4.27.0",
              "versionType": "custom",
              "lessThanOrEqual": "4.27.7M"
            },
            {
              "status": "affected",
              "version": "4.26.8M",
              "versionType": "custom",
              "lessThanOrEqual": "4.26.8M"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-04-12T21:15:18.183",
  "references": [
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/17240-security-advisory-0085",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@arista.com"
    },
    {
      "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/17240-security-advisory-0085",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@arista.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic."
    }
  ],
  "lastModified": "2026-06-17T05:39:30.483",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arista:cloudeos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D1A5002-07BD-4669-A7C9-E47A28C3F39C",
              "versionEndExcluding": "4.26.9m",
              "versionStartIncluding": "4.26.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:cloudeos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FEF7B98-AD0E-4DE3-912D-DDC39FE4C3D7",
              "versionEndExcluding": "4.27.8m",
              "versionStartIncluding": "4.27.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:cloudeos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA82CE8C-A95E-48B9-8E61-09429FFBC0DD",
              "versionEndExcluding": "4.28.5m",
              "versionStartIncluding": "4.28.0"
            },
            {
              "criteria": "cpe:2.3:o:arista:cloudeos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0769DED3-64E8-4EEC-95BD-CDB18C848B8E",
              "versionEndExcluding": "4.29.2f",
              "versionStartIncluding": "4.29.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arista:dca-200-veos:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6C9985E3-D496-473F-A806-022EC164EF96"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@arista.com"
}