CVE-2019-18948: Arista Eos

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train.

Affected products

  • Arista Eos: from 4.21.0, up to and including 4.21.8m; from 4.22.0, up to and including 4.22.3m; from 4.23.0, up to and including 4.23.1f; version 4.15 only; version 4.16 only; version 4.17 only; …

Published 2020-04-16. Last modified 2026-06-17.