Database/Firmware, BMC & network fabric

Arista EOS (BGP UPDATE): Malformed path attribute in a BGP UPDATE from a peer causes denial of service
CVSS 7.5CVE-2018-5254Firmware, BMC & network fabriccurated
Impact
Malformed path attribute in a BGP UPDATE from a peer causes denial of service
Who can reach it
Network, from a BGP peer
What to do
EOS upgrade; relevant where the fabric peers with a transit provider or a customer-controlled router
References
Related entries
- Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agentCVE-2019-18948 · Arista EOS (VxLAN agent)High
- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationCVE-2019-6193 · Lenovo XClarity Administrator (LXCA) - unauthenticated config file accessHigh
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionCVE-2020-11487 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): Default SNMP community strings on the DGX BMCCVE-2020-11489 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): Hard-coded RC4 key in the DGX BMC firmwareCVE-2020-11615 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): The PRNG used by the IPMI implementation in the BMC's JSOL packageCVE-2020-11616 · NVIDIA DGX BMC (AMI firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.