CVE-2020-15898: Arista Eos

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train.

Affected products

  • Arista Eos: from 4.21.0f, up to and including 4.21.4.1f; from 4.21.0f, up to and including 4.21.11m; from 4.22.0f, up to and including 4.22.6m; from 4.23.0f, up to and including 4.23.4m; from 4.24.0f, up to and including 4.24.2.1f

Published 2020-12-28. Last modified 2026-06-17.