vulnerability

Security Advisory 0052

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Oct 7, 2020
Added
Sep 4, 2024
Modified
Jan 14, 2026

Description

This advisory documents a vulnerability in Arista's CloudVision eXchange (CVX) server affecting the ControllerOob agent. If the CVX server receives a malformed control-plane packet, the ControllerOob agent could crash and restart, potentially causing connection flaps between the CVX server and managed Arista devices. In a High Availability setup, this could trigger a failover of the Master Node. The vulnerability does not directly impact production traffic but could affect the CVX server's ability to manage the network.

Solution

upgrade-solution-cve-2020-13100
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.