CVE-2024-6437: Arista Networks Eos-Policy Based Routing Pbr

Medium severity, CVSS 5.8. EPSS: 0.5% chance of exploitation in the next 30 days.

On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.

Affected products

  • Arista Networks Eos-Policy Based Routing Pbr: from 4.32.0F, up to and including 4.32.1F; from 4.31.0M, up to and including 4.31.4M; from 4.30.0M, up to and including 4.30.7M; from 4.29.0M, up to and including 4.29.9M; from 4.28.0M, up to and including 4.28.11M; from 4.27.0M, up to and including 4.27.12M; …
  • Arista Networks Eos - Bgp Flowspec: from 4.32.0F, up to and including 4.32.1F; from 4.31.0M, up to and including 4.31.4M; from 4.30.0M, up to and including 4.30.7M; from 4.29.0M, up to and including 4.29.9M; from 4.28.0M, up to and including 4.28.11M; from 4.27.0M, up to and including 4.27.12M; …
  • Arista Networks Eos - Interface Traffic Policy: from 4.32.0F, up to and including 4.32.1F; from 4.31.0M, up to and including 4.31.4M; from 4.30.0M, up to and including 4.30.7M; from 4.29.0M, up to and including 4.29.9M; from 4.28.0M, up to and including 4.28.11M; from 4.27.2F, up to and including 4.27.12F

Published 2025-01-10. Last modified 2026-06-17.