CVE Database
/

CVE-2024-6437

Back to search

CVE-2024-6437

Published: Jan 10, 2025

Modified: Jan 10, 2025

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.

VendorProductVersions

Arista Networks

EOS-Policy Based Routing (PBR)

affected
4.32.0F - <= 4.32.1F
affected
4.31.0M - <= 4.31.4M
affected
4.30.0M - <= 4.30.7M
affected
4.29.0M - <= 4.29.9M
affected
4.28.0M - <= 4.28.11M

+7 more versions

Arista Networks

EOS - BGP Flowspec

affected
4.32.0F - <= 4.32.1F
affected
4.31.0M - <= 4.31.4M
affected
4.30.0M - <= 4.30.7M
affected
4.29.0M - <= 4.29.9M
affected
4.28.0M - <= 4.28.11M

+7 more versions

Arista Networks

EOS - Interface Traffic Policy

affected
4.32.0F - <= 4.32.1F
affected
4.31.0M - <= 4.31.4M
affected
4.30.0M - <= 4.30.7M
affected
4.29.0M - <= 4.29.9M
affected
4.28.0M - <= 4.28.11M

+1 more versions

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

None

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now