CVE-2024-9448 – Arista EOS Traffic Policy Unvalidated Packet Forwarding

The following table lists the changes that have been made to the
CVE-2024-9448 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    May. 08, 2025

    Action Type Old Value New Value
    Added Description On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
    Added CWE CWE-1284
    Added Reference https://www.arista.com/en/support/advisories-notices/security-advisory/21121-security-advisory-0112
Share the Post:

Related Posts