CVE-2019-17596: Arista Cloudvision Portal
High severity, CVSS 7.5. EPSS: 4.7% chance of exploitation in the next 30 days.
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
Affected products
- Arista Cloudvision Portal: from 2018.1.0, up to and including 2018.2.3; version 2019.1.0 only; version 2019.1.1 only; version 2019.1.2 only
- Arista Eos: up to and including 4.23.1f
- Arista Mos: up to and including 0.25
- Arista Terminattr: up to and including 1.7.2
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Golang Go: from 1.12, before 1.12.11 (fixed in 1.12.11); from 1.13, before 1.13.2 (fixed in 1.13.2)
- Opensuse Leap: version 15.0 only; version 15.1 only
- Red Hat Developer Tools: version 1.0 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Enterprise Linux Server: version 8.1 only
Published 2019-10-24. Last modified 2026-06-17.