CVE-2023-24510 describes a vulnerability in Arista EOS where a specially crafted DHCP packet can cause the DHCP relay agent to restart. This high-severity vulnerability (CVSS 7.5) can be exploited remotely over the network with low attack complexity, leading to a denial of service impact. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations using affected Arista products should still address this potential disruption.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.25.10mCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.26.0, < 4.26.10mCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.27.0, < 4.27.10mCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.28.0, < 4.28.7mCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* | ||
>= 4.29.0, < 4.29.2fCPE matchmatch criteria | cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.