mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-07 05:28:59 +00:00
399 lines
15 KiB
JSON
399 lines
15 KiB
JSON
{
|
|
"id": "CVE-2020-15898",
|
|
"sourceIdentifier": "cve@mitre.org",
|
|
"published": "2020-12-28T19:15:12.783",
|
|
"lastModified": "2021-01-04T20:30:52.173",
|
|
"vulnStatus": "Analyzed",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version 4.21.4.1F and below releases in the 4.21.x train; EOS X-Series versions 4.21.11M and below releases in the 4.21.x train; 4.22.6M and below releases in the 4.22.x train; 4.23.4M and below releases in the 4.23.x train; 4.24.2.1F and below releases in the 4.24.x train."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "En Arista EOS, los paquetes malformados pueden ser incorrectamente reenviados a trav\u00e9s de los l\u00edmites de la VLAN en una direcci\u00f3n. Esta vulnerabilidad solo es susceptible de explotaci\u00f3n por tr\u00e1fico unidireccional (por ejemplo, UDP) y no por tr\u00e1fico bidireccional (por ejemplo, TCP). Esto afecta a: plataformas EOS 7170 versi\u00f3n 4.21.4.1F y versiones por debajo en el tren 4.21.x; EOS X-Series versiones 4.21.11M y versiones por debajo en el tren 4.21.x; 4.22.6M y versiones por debajo en el tren 4.22.x; 4.23.4M y versiones por debajo en el tren 4.23.x; 4.24.2.1F y versiones por debajo en el tren 4.24.x"
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "LOW",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 5.3,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 1.4
|
|
}
|
|
],
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
|
|
"accessVector": "NETWORK",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "PARTIAL",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 5.0
|
|
},
|
|
"baseSeverity": "MEDIUM",
|
|
"exploitabilityScore": 10.0,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "NVD-CWE-noinfo"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
|
|
"versionStartIncluding": "4.21.0f",
|
|
"versionEndIncluding": "4.21.4.1f",
|
|
"matchCriteriaId": "D74FB457-3B38-49B2-80A7-A0541BAAFBD7"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7170-32c:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E8EFEEA5-0FC4-4FFC-BF5D-BDBAA1B55C70"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7170-32cd:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B2959C68-8731-4F37-B9E7-61E5936D3D8E"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7170-64c:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D6FB3395-8D13-4477-A46E-37A88272CFAB"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "AND",
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
|
|
"versionStartIncluding": "4.21.0f",
|
|
"versionEndIncluding": "4.21.11m",
|
|
"matchCriteriaId": "1F0F53EB-B0DE-42AB-A9F9-FFBAFC5F223A"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
|
|
"versionStartIncluding": "4.22.0f",
|
|
"versionEndIncluding": "4.22.6m",
|
|
"matchCriteriaId": "188A9EBD-1DD4-4111-A66D-67C0A0035662"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
|
|
"versionStartIncluding": "4.23.0f",
|
|
"versionEndIncluding": "4.23.4m",
|
|
"matchCriteriaId": "F80FCF7B-38CD-43B5-82EE-139A0D249D70"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*",
|
|
"versionStartIncluding": "4.24.0f",
|
|
"versionEndIncluding": "4.24.2.1f",
|
|
"matchCriteriaId": "B02B2F63-75D5-4C8A-BAD3-CDFE1A31CE48"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050cx3-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E1FF0290-C671-4ABC-8A12-05E4D55FC4AE"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050cx3m-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "828C6E4F-814A-4060-8F5E-7FF359C8739C"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050qx-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "253D74DE-97F5-40F3-B179-D2D4442C57FD"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050qx2-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "75E03F9E-522F-4D9B-9267-09E2550B5465"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx-128:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "895A7AFD-BE76-47F5-B67B-6279046E4274"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx-64:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "74E258EC-EA50-4185-AA35-5D963C359E74"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx-72q:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "1482D4FC-60B9-4C89-B892-71AA3E1031F3"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx2-128:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "C99D84E9-2229-459E-AE90-49C2EF670884"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx2-72q:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D922C725-1139-4DD4-92FC-9FF15E35CE62"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx3-48c8:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "FE35C17F-0C60-4A40-9949-D4C5D94D1D7A"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx3-48yc:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "07BA078E-30B7-4E2C-B240-BF64E98143E9"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx3-48yc12:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EBFD0706-CACB-40FA-A41B-46B39C6E1D33"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx3-48yc8:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5951D243-CB68-4B41-A913-D879CE502795"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050sx3-96yc8:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "73156612-D338-4E20-8C82-0E65DAA72331"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050tx-48:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "78E7CDCC-ADC6-4854-BFC4-72DA47C5F10B"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050tx-64:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2B03678D-AD7B-4B1A-8E6A-1811DD8B1483"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050tx-72q:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E803639C-13A1-48CA-A589-C83654AE454F"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050tx2-128:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A495D282-D3DC-4D18-AB72-2358834C238E"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7050tx3-48c8:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "388C57D8-4B3C-4E5D-84AA-0CB7506F825A"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7060cx-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D518C8D5-A86B-46E5-A646-8939BFA2E116"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7060cx2-32s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "A1608297-7079-4F3B-857E-708B74E944D9"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7060dx4-32:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "806A01C5-231D-4F9D-A292-E9DD706A0C66"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7060px4-32:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "AC10746F-8FC0-49EF-BB9C-EC49B734DFA3"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7060sx2-48yc6:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "26582E98-B710-46D7-B8F2-9286E0592FA6"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:720xp-24y6:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "7AFDBCBB-2C1A-4B88-AE28-EF63D5B9EDD2"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:720xp-24zy4:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "58757129-BF9C-4BD8-B692-BB57023F8A48"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:720xp-48y6:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "2756BB4B-1053-4EAC-AC0B-785FD5039D5F"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:720xp-48zc2:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "40D36540-7723-4284-A207-6BD27728CA25"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:720xp-96zc2:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DF95CB28-E010-4A1D-A746-F9DDF015868F"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7250qx-64:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0DD95B3B-D655-42DC-85C2-2C6FDBCC77F1"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7260cx:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "E40D14DE-BAFB-461F-9AA7-E3EDC2D8D468"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7260cx3:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "901E5B76-0EB7-4EAD-A281-15B9F78041AB"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7260cx3-64:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "49BAE58E-F4B5-4C8F-9EEB-5A0F38A96F0C"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7260qx:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "EE1DE992-9BFA-4794-82F4-66F464BB384E"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7300x-32q:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "DDF8A65D-6FBC-4C38-8B45-418E6C5EB16C"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7300x-64s:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8F088D51-24F4-49AD-8397-73D1EAF45F56"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7300x-64t:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "69BA5C6D-40C0-4AA3-AC10-D7F097D8EDD9"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7300x3-32c:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "0040BDDF-D711-4619-9E96-96EFBD33CAA0"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7300x3-48yc4:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "D4AA716D-CAD1-4689-8A26-977A2E5F869E"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7304x3:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "78FE473B-CA6E-4E8D-8DBF-676B1ECBB185"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7308x3:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "9F1EF943-154C-4B5B-B803-E186FEA8C5A0"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7320x-32c:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "5AD08CBF-6F42-4F98-B413-F65C5613BE6B"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7324x:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "B8862F74-E399-41EE-A081-62D99A7C1755"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7328x:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "8F16261D-639F-4CAB-BDA6-EF3F277E663C"
|
|
},
|
|
{
|
|
"vulnerable": false,
|
|
"criteria": "cpe:2.3:h:arista:7368x4:-:*:*:*:*:*:*:*",
|
|
"matchCriteriaId": "161DB0D9-9BAC-4546-88D3-5547F4B6149C"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://www.arista.com/en/support/advisories-notices/security-advisories/11996-security-advisory-56",
|
|
"source": "cve@mitre.org",
|
|
"tags": [
|
|
"Exploit",
|
|
"Vendor Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |