CVE-2020-10188: Arista Eos
Critical severity, CVSS 9.8. EPSS: 74.3% chance of exploitation in the next 30 days.
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
Affected products
- Arista Eos: up to and including 4.20.15; from 4.21.0, up to and including 4.21.10m; from 4.22, up to and including 4.22.4m; from 4.23, up to and including 4.23.3m; version 4.24.0f only
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only; version 32 only
- Juniper Junos: version 12.3 only; version 12.3r12 only; version 12.3x48 only; version 12.3x50 only; version 15.1 only; version 15.1x49 only; …
- Netkit Telnet Project Netkit Telnet: up to and including 0.17
- Oracle Communications Performance Intelligence Center: version 10.4.0.2 only
Published 2020-03-06. Last modified 2026-06-17.