CVE-2024-5872: Arista Networks Eos

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.

Affected products

  • Arista Networks Eos: from 4.32.0F, up to and including 4.32.2F; from 4.31.0M, up to and including 4.31.4M; from 4.30.0M, up to and including 4.30.7M; from 4.29.0M, up to and including 4.29.8M; from 4.28.1F, up to and including 4.28.11F

Published 2025-01-10. Last modified 2026-06-17.