Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54607 | On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. |
Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades CVE-2024-11185 has been fixed in the following releases: * 4.30.10M and later releases in the 4.30.x train * 4.31.7M and later releases in the 4.31.x train * 4.32.5M and later releases in the 4.32.x train * 4.33.2F and later releases in the 4.33.x train
Workaround
There are no workarounds.
Wed, 28 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 May 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. | |
| Title | On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2025-05-28T13:34:52.088Z
Reserved: 2024-11-13T17:02:27.536Z
Link: CVE-2024-11185
Updated: 2025-05-28T13:34:48.849Z
Status : Awaiting Analysis
Published: 2025-05-27T23:15:20.580
Modified: 2025-05-28T15:01:30.720
Link: CVE-2024-11185
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD