CyberRota Analysis
AI-GeneratedArista EOS platforms with dual switch cards and configured ingress Security ACLs on shared Switched Virtual Interfaces (SVIs) are vulnerable to a malfunction where restarting the secondary switch card or inserting a new one can disable the ACLs. This may lead to improper packet filtering, potentially allowing unauthorized traffic. Organizations using affected Arista equipment should prioritize this issue to ensure network security and proper ACL functionality.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.