CVE-2024-9448
Last modified
CVE-2024-9448 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-9448?
How severe is CVE-2024-9448?
How do I fix CVE-2024-9448?
Are you affected by CVE-2024-9448?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
