SB2025051723 - Denial of service in Arista EOS



SB2025051723 - Denial of service in Arista EOS

Published: May 17, 2025

Security Bulletin ID SB2025051723
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2024-6437)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when handling traffic redirection. A remote attacker can bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.

Successful exploitation of the vulnerability requires one of the following features configured to redirect IP traffic to a next hop:

- policy-based routing (PBR)

- BGP Flowspec

- or interface traffic policy


Remediation

Install update from vendor's website.