Impact
The vulnerability allows traffic that should be dropped based on unicast reverse path forwarding checks to be processed and forwarded. The result is that packets from unauthorized or misrouted sources are forwarded, potentially exposing the network to unwanted traffic or service disruption. The weakness resides in insufficient enforcement of uRPF checks, a permission level degradation flaw.
Affected Systems
Affected devices are Arista EOS routers running EOS releases before 4.35.5M in the 4.35.x train or before 4.36.0F in the 4.36.x train.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact, and the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary with network access sending permitted traffic that bypasses uRPF checks; exploitation would require crafting traffic that satisfies the loose mode constraints, which may be feasible with network-level privileges. No hotfix is available, and no workaround exists, so the only available mitigation is an upgrade.
OpenCVE Enrichment