Impact
The VeloCloud Edge and Gateway have an out‑of‑bounds write condition in the VCMP tunnel protocol that processes tunneled IP fragments between authenticated overlay neighbors. The flaw can cause the vulnerable process to terminate and restart, resulting in a brief traffic disruption. The vulnerability is limited to authenticated overlay peers and does not allow unauthenticated hosts to trigger the logic.
Affected Systems
Arista Networks VeloCloud Edge and Arista Networks VeloCloud Gateway devices running firmware versions 5.2.7.0 or newer in the 5.2.x train, 6.1.5.0 or newer in the 6.1.x train, 6.4.2.0 or newer in the 6.4.x train, or 7.0.0 or later.
Risk and Exploitability
The CVSS score of 8.2 classifies it as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation. The attack requires authenticated overlay peers, and the CVE is not listed in the CISA KEV catalog, which further suggests limited real‑world exploitation. Nevertheless, any successful exploit would cause a transient service disruption that could compound in a large overlay network.
OpenCVE Enrichment