For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
Solution:
Workaround:
The product does not properly control the allocation and maintenance of a limited resource.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Link | Tags |
---|---|
https://www.arista.com/en/support/advisories-notices/security-advisory/15439-security-advisory-0076 | vendor advisory mitigation exploit |