#VU109380 Input validation error in Arista Extensible Operating System (EOS) - CVE-2024-5872
Published: May 17, 2025
Arista Extensible Operating System (EOS)
Arista Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when handling VLAN tags. A remote attacker on the local network can send packets with specially crafted VLAN tags and perform a denial of service (DoS) attack or cause incorrect control plane behavior.