CVE-2020-13100: Arista Cloudvision Exchange

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.

Affected products

  • Arista Cloudvision Exchange: from 4.21.5f, before 4.21.12m (fixed in 4.21.12m); from 4.22.0, before 4.22.7m (fixed in 4.22.7m); from 4.23.0, before 4.23.5m (fixed in 4.23.5m); from 4.24.0, before 4.24.2f (fixed in 4.24.2f)

Published 2020-10-26. Last modified 2026-06-17.