SB2025051729 - Cleartext transmission of sensitive information in Arista EOS
Published: May 17, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2024-12378)
CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error in Tunnelsec agent. Restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
Remediation
Install update from vendor's website.