Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages
Vulnerability Description
In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
输入验证不恰当
Vulnerability Title
Arista CloudVision eXchange 安全漏洞
Vulnerability Description
Arista CloudVision eXchange是美国Arista公司的一个面向数据中心和企业网络的控制平面交换平台。 Arista CloudVision eXchange存在安全漏洞,该漏洞源于EOS交换机对来自CVX服务器的特定畸形消息缺乏弹性,CVX服务器对来自EOS交换机的特定畸形消息也缺乏弹性,可能导致Sysdb代理崩溃或CVX代理崩溃,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A