CVE-2023-24548: Arista Eos
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.
Affected products
- Arista Eos: from 4.22.1f, up to and including 4.22.13m; from 4.23.0, up to and including 4.23.14m; from 4.24.0, up to and including 4.24.11m; version 4.25.0f only
Published 2023-08-29. Last modified 2026-06-17.