CVE-2020-17355: Arista Eos
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
Affected products
- Arista Eos: from 4.21.0, before 4.21.12m (fixed in 4.21.12m); from 4.22, before 4.22.7m (fixed in 4.22.7m); from 4.23, before 4.23.5m (fixed in 4.23.5m); from 4.24.0, before 4.24.2f (fixed in 4.24.2f)
Published 2020-10-21. Last modified 2026-06-17.