Database/Firmware, BMC & network fabric

Arista EOS (VxLAN agent): Malformed ARP packets crash the VxLAN software forwarding agent
CVSS 7.5CVE-2019-18948Firmware, BMC & network fabriccurated
Impact
Malformed ARP packets crash the VxLAN software forwarding agent — a tenant VM can take down overlay forwarding
Who can reach it
Network, from inside a tenant VLAN
What to do
EOS upgrade with failover; notable because the trigger comes from tenant traffic, not the management plane
References
Related entries
- Lenovo XClarity Administrator (LXCA) - unauthenticated config file access: Unauthenticated access to LXCA configurationCVE-2019-6193 · Lenovo XClarity Administrator (LXCA) - unauthenticated config file accessHigh
- NVIDIA DGX BMC (AMI firmware): A hard-coded RSA-1024 key with weak ciphers in the BMC firmware means the encryptionCVE-2020-11487 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): Default SNMP community strings on the DGX BMCCVE-2020-11489 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): Hard-coded RC4 key in the DGX BMC firmwareCVE-2020-11615 · NVIDIA DGX BMC (AMI firmware)High
- NVIDIA DGX BMC (AMI firmware): The PRNG used by the IPMI implementation in the BMC's JSOL packageCVE-2020-11616 · NVIDIA DGX BMC (AMI firmware)High
- AMD processors - transient non-canonical loads and stores using lower 48 address bits: Combined with specific softwareCVE-2020-12965 · AMD processors - transient non-canonical loads and stores using lower 48 address bitsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.