SB2025051729 - Cleartext transmission of sensitive information in Arista EOS
Published: May 17, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext transmission of sensitive information (CVE-ID: CVE-2024-12378)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error in Tunnelsec agent. Restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
Remediation
Install update from vendor's website.