
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Arista EOS affecting VxLAN implementation where specific malformed ARP packets can impact the software forwarding of VxLAN packets. The vulnerability was assigned CVE-2019-18948 with a CVSSv3 Base Score of 7.5. The affected versions include EOS 4.21.8M and below releases in the 4.21.x train, 4.22.3M and below releases in the 4.22.x train, 4.23.1F and below releases in the 4.23.x train, and all releases in 4.15, 4.16, 4.17, 4.18, 4.19, 4.20 code train (Arista Advisory).
The vulnerability exists in Arista's EOS VxLAN code and can allow attackers to crash the VxlanSwFwd agent. While the mappings already programmed in hardware are not affected, specific malformed ARP packets can impact the software forwarding of VxLAN packets. The issue is tracked internally by Arista as Bug 364633 (VxLAN on MLAG configured system) and Bug 420663 (VxLAN routing setup). The vulnerability has a CVSSv3 Base Score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicating high severity (Arista Advisory).
An attack exploiting this vulnerability could result in the crash of the VxlanSwFwd agent. While this wouldn't impact other agents or traffic forwarding functions, software forwarding of VxLAN packets may be affected leading to traffic loss. However, existing ARP entries or hardware forwarding remain unimpacted during such events (Arista Advisory).
The vulnerability can be triggered by sending specific malformed ARP packets to affected systems running VxLAN. The attack can be executed remotely without requiring authentication or user interaction, as indicated by the CVSSv3 vector string (AV:N/AC:L/PR:N/UI:N) (Arista Advisory).
Arista recommends restricting public access to internal devices as a security best practice. The vulnerability is fixed in EOS versions 4.21.9M and later releases, 4.22.4M and later releases, and 4.23.2F and later releases. For systems unable to upgrade immediately, version-specific hotfixes are available as EOS extensions. When applying the hotfix, the VxlanSwFwd agent will restart, causing a brief disruption lasting 5 seconds or less during which new ARP VxLAN requests and replies will be missed, though existing ARP entries remain unaffected (Arista Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."