CVE-2019-14810 describes a race condition vulnerability in the Label Distribution Protocol (LDP) implementation within Arista EOS, affecting various Arista 7000 series switches and EOS versions. This flaw allows a malicious peer to establish an LDP session, potentially leading to a Denial of Service (DoS) attack on route updates and an Out of Memory (OOM) condition, disrupting traffic forwarding. Rated Medium severity (CVSS 5.9), exploitation requires high attack complexity but no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.19, <= 4.19.12mCPE matchmatch criteria | cpe:2.3:o:arista:extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 4.20, <= 4.20.14mCPE matchmatch criteria | cpe:2.3:o:arista:extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 4.21.0f, <= 4.21.2.3fCPE matchmatch criteria | cpe:2.3:o:arista:extensible_operating_system:*:*:*:*:*:*:*:* | ||
>= 4.21.3f, <= 4.21.7CPE matchmatch criteria | cpe:2.3:o:arista:extensible_operating_system:*:*:*:*:*:*:*:* | ||
4.17CPE matchmatch criteria | cpe:2.3:o:arista:extensible_operating_system:4.17:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.