CVE-2020-17355
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-17355 is a security vulnerability affecting Arista EOS network operating system versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F. The vulnerability was disclosed on October 7th, 2020, and allows remote attackers to cause a denial of service condition through crafted malformed DHCP packets (Vendor Advisory, NVD).

Technical details

The vulnerability exists in EOS where a malformed DHCP packet can lead to an incorrect route being installed when the 'ipv6 dhcp relay install routes' option is configured. The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility with low attack complexity and no required privileges or user interaction (NVD, Vendor Advisory).

Impact

The exploitation of this vulnerability can result in the restart of various system agents including SandL3Unicast, Ira, Arp, or Snmp agents. The impact manifests as agent restarts or feature usability issues, specifically affecting devices with the 'ipv6 dhcp relay install routes' configuration on routed ports where DHCP Relay is listening (Vendor Advisory).

Exploitability

The vulnerability requires the 'ipv6 dhcp relay install routes' configuration to be applied for exploitation. As of the advisory's release, Arista had not received any reports of this vulnerability being exploited maliciously in the wild (Vendor Advisory).

Mitigation and workarounds

Several mitigation options are available: 1) Restrict public access to DHCP servers or internal devices sending DHCPv6 packets, 2) Configure Access-Control Lists (ACLs) on DHCP listening ports to allow access only from trusted DHCP servers, 3) Remove 'ipv6 dhcp relay install routes' from the configuration as a temporary workaround, or 4) Upgrade to remediated versions: 4.24.2F, 4.23.5M, 4.22.7M, or 4.21.12M (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management