Resource management error in Arista Extensible Operating System (EOS) - CVE-2024-6437

 

Resource management error in Arista Extensible Operating System (EOS) - CVE-2024-6437

Published: May 17, 2025


Vulnerability identifier: #VU109381
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-6437
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when handling traffic redirection. A remote attacker can bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.

Successful exploitation of the vulnerability requires one of the following features configured to redirect IP traffic to a next hop:

- policy-based routing (PBR)

- BGP Flowspec

- or interface traffic policy


Affected software

Arista Extensible Operating System (EOS)

How to mitigate CVE-2024-6437

Install updates from vendor's website.

Arista Extensible Operating System (EOS) - addressed in versions 4.29.10M, 4.30.8M, 4.31.5M, 4.32.2F

External References

Related Security Bulletins