Arista EOS
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*
- <= 4.32.2F
- <= 4.31.6M
- <= 4.30.8M
- <= 4.29.9M
- <= 4.28.12M
- <= 4.27.12M
A vulnerability exists in Arista EOS platforms with secure VxLAN configured. Restarting the Tunnelsec agent can cause packets to be transmitted unencrypted over the secure VxLAN tunnels. This issue affects several EOS versions and is present on specific Arista EOS-based products.
Exploitation of this vulnerability leads to the cleartext transmission of sensitive information over secure VxLAN tunnels, potentially allowing for interception and analysis of the transmitted data.
Users are advised to upgrade to Arista EOS versions 4.33.0F, 4.32.3M, 4.31.7M, 4.30.9M, or 4.29.10M. For more information on upgrading, consult the EOS User Manual: Upgrades and Downgrades.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.