CVE-2020-26569
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M and below releases in the 4.21.x train; 4.22.7M and below releases in the 4.22.x train; 4.23.5M and below releases in the 4.23.x train; 4.24.2F and below releases in the 4.24.x train.
Published:Dec 28, 2020
Last Modified:Nov 21, 2024
EPS:Dec 28, 2020
EPSS Score:0.00389
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Arista
Product
7010t-48
Arista
7010t-48
Vendor
Arista
Product
7050cx3-32s
Arista
7050cx3-32s
Vendor
Arista
Product
7050cx3m-32s
Arista
7050cx3m-32s
Vendor
Arista
Product
7050qx-32s
Arista
7050qx-32s
Vendor
Arista
Product
7050qx2-32s
Arista
7050qx2-32s
Vendor
Arista
Product
7050sx-128
Arista
7050sx-128
Vendor
Arista
Product
7050sx-64
Arista
7050sx-64
Vendor
Arista
Product
7050sx-72q
Arista
7050sx-72q
Vendor
Arista
Product
7050sx2-128
Arista
7050sx2-128
Vendor
Arista
Product
7050sx2-72q
Arista
7050sx2-72q
Vendor
Arista
Product
7050sx3-48c8
Arista
7050sx3-48c8
Vendor
Arista
Product
7050sx3-48yc
Arista
7050sx3-48yc
Vendor
Arista
Product
7050sx3-48yc12
Arista
7050sx3-48yc12
Vendor
Arista
Product
7050sx3-48yc8
Arista
7050sx3-48yc8
Vendor
Arista
Product
7050sx3-96yc8
Arista
7050sx3-96yc8
Vendor
Arista
Product
7050tx-48
Arista
7050tx-48
Vendor
Arista
Product
7050tx-64
Arista
7050tx-64
Vendor
Arista
Product
7050tx-72q
Arista
7050tx-72q
Vendor
Arista
Product
7050tx2-128
Arista
7050tx2-128
Vendor
Arista
Product
7050tx3-48c8
Arista
7050tx3-48c8
Vendor
Arista
Product
7060cx-32s
Arista
7060cx-32s
Vendor
Arista
Product
7060cx2-32s
Arista
7060cx2-32s
Vendor
Arista
Product
7060dx4-32
Arista
7060dx4-32
Vendor
Arista
Product
7060px4-32
Arista
7060px4-32
Vendor
Arista
Product
7060sx2-48yc6
Arista
7060sx2-48yc6
Vendor
Arista
Product
720xp-24y6
Arista
720xp-24y6
Vendor
Arista
Product
720xp-24zy4
Arista
720xp-24zy4
Vendor
Arista
Product
720xp-48y6
Arista
720xp-48y6
Vendor
Arista
Product
720xp-48zc2
Arista
720xp-48zc2
Vendor
Arista
Product
720xp-96zc2
Arista
720xp-96zc2
Vendor
Arista
Product
7250qx-64
Arista
7250qx-64
Vendor
Arista
Product
7260cx
Arista
7260cx
Vendor
Arista
Product
7260cx3
Arista
7260cx3
Vendor
Arista
Product
7260cx3-64
Arista
7260cx3-64
Vendor
Arista
Product
7260qx
Arista
7260qx
Vendor
Arista
Product
7300x-32q
Arista
7300x-32q
Vendor
Arista
Product
7300x-64s
Arista
7300x-64s
Vendor
Arista
Product
7300x-64t
Arista
7300x-64t
Vendor
Arista
Product
7300x3-32c
Arista
7300x3-32c
Vendor
Arista
Product
7300x3-48yc4
Arista
7300x3-48yc4
Vendor
Arista
Product
7304x3
Arista
7304x3
Vendor
Arista
Product
7308x3
Arista
7308x3
Vendor
Arista
Product
7320x-32c
Arista
7320x-32c
Vendor
Arista
Product
7324x
Arista
7324x
Vendor
Arista
Product
7328x
Arista
7328x
Vendor
Arista
Product
7368x4
Arista
7368x4
Vendor
Arista
Product
Eos
Arista
Eos
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
