
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-17355 is a security vulnerability affecting Arista EOS network operating system versions before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F. The vulnerability was disclosed on October 7th, 2020, and allows remote attackers to cause a denial of service condition through crafted malformed DHCP packets (Vendor Advisory, NVD).
The vulnerability exists in EOS where a malformed DHCP packet can lead to an incorrect route being installed when the 'ipv6 dhcp relay install routes' option is configured. The vulnerability has a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating network accessibility with low attack complexity and no required privileges or user interaction (NVD, Vendor Advisory).
The exploitation of this vulnerability can result in the restart of various system agents including SandL3Unicast, Ira, Arp, or Snmp agents. The impact manifests as agent restarts or feature usability issues, specifically affecting devices with the 'ipv6 dhcp relay install routes' configuration on routed ports where DHCP Relay is listening (Vendor Advisory).
The vulnerability requires the 'ipv6 dhcp relay install routes' configuration to be applied for exploitation. As of the advisory's release, Arista had not received any reports of this vulnerability being exploited maliciously in the wild (Vendor Advisory).
Several mitigation options are available: 1) Restrict public access to DHCP servers or internal devices sending DHCPv6 packets, 2) Configure Access-Control Lists (ACLs) on DHCP listening ports to allow access only from trusted DHCP servers, 3) Remove 'ipv6 dhcp relay install routes' from the configuration as a temporary workaround, or 4) Upgrade to remediated versions: 4.24.2F, 4.23.5M, 4.22.7M, or 4.21.12M (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."