{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "title": "Security Advisory 88",
    "tracking": {
      "current_release_date": "2023-08-23T23:39:36Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 88",
      "initial_release_date": "2023-08-23T23:39:36Z",
      "revision_history": [
        {
          "date": "2023-08-23T23:39:36Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.3M",
                    "product": {
                      "name": "EOS version 4.28.3M",
                      "product_id": "CSAFPID-7"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.2",
                    "product": {
                      "name": "EOS version 4.28.2",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.2F",
                    "product": {
                      "name": "EOS version 4.28.2F",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.5.1M",
                    "product": {
                      "name": "EOS version 4.28.5.1M",
                      "product_id": "CSAFPID-9"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.5M",
                    "product": {
                      "name": "EOS version 4.28.5M",
                      "product_id": "CSAFPID-10"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.29.2",
                    "product": {
                      "name": "EOS version 4.29.2",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.2.2F",
                    "product": {
                      "name": "EOS version 4.28.2.2F",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.2.1F",
                    "product": {
                      "name": "EOS version 4.28.2.1F",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.23.1",
                    "product": {
                      "name": "EOS version 4.23.1",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.6",
                    "product": {
                      "name": "EOS version 4.28.6",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.28.4M",
                    "product": {
                      "name": "EOS version 4.28.4M",
                      "product_id": "CSAFPID-8"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
                "product": {
                  "name": "Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
                  "product_id": "CSAFPID-12"
                }
              },
              {
                "category": "product_version",
                "name": "Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
                "product": {
                  "name": "Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
                  "product_id": "CSAFPID-11"
                }
              }
            ],
            "category": "product_family",
            "name": "Hotfixes"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ],
    "relationships": [
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.5.1M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-25"
        },
        "product_reference": "CSAFPID-9",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.5.1M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-18"
        },
        "product_reference": "CSAFPID-9",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.5M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-19"
        },
        "product_reference": "CSAFPID-10",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-22"
        },
        "product_reference": "CSAFPID-6",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.4M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-17"
        },
        "product_reference": "CSAFPID-8",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2.2F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-21"
        },
        "product_reference": "CSAFPID-5",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2.2F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-14"
        },
        "product_reference": "CSAFPID-5",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.5M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-26"
        },
        "product_reference": "CSAFPID-10",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-15"
        },
        "product_reference": "CSAFPID-6",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.3M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-16"
        },
        "product_reference": "CSAFPID-7",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.4M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-24"
        },
        "product_reference": "CSAFPID-8",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.3M with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-23"
        },
        "product_reference": "CSAFPID-7",
        "relates_to_product_reference": "CSAFPID-12"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2.1F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix 1.0",
          "product_id": "CSAFPID-13"
        },
        "product_reference": "CSAFPID-4",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.28.2.1F with Hotfix SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix 1.0",
          "product_id": "CSAFPID-20"
        },
        "product_reference": "CSAFPID-4",
        "relates_to_product_reference": "CSAFPID-12"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-3646",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "765111,829136"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.\n",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "CVE-2023-3646 Is tracked by BUG829136. In order to be vulnerable to the CVE a system must already be impacted by BUG765111, which is a non CVE known issue. In order to be impacted by BUG765111, the following conditions must be met:\n\nMirroring to multiple destinations must be configured:\nswitch(config)#show monitor session\n\nSession s1\n------------------------\n\nSources:\n\nBoth Interfaces:        Et1/1\n\nDestination Ports:\n\n    Et9/1 :  active\n    Et10/1 :  active\n\nIn the above example two destinations, Et9/1 and Et10/1, are configured.\n\nMirroring config must be added with mirror destination being ethernet port, example:\nswitch # show running-config | section monitor\nmonitor session APCON destination Ethernet54/1\n\nIn the above example the argument after destination is an Ethernet port.\n",
          "title": "765111: Required Config for Exploitation"
        },
        {
          "category": "other",
          "text": "CVE-2023-3646 Is tracked by BUG829136. In order to be vulnerable to the CVE a system must already be impacted by BUG765111, which is a non CVE known issue. In order to be impacted by BUG765111, the following conditions must be met:\n\nMirroring to multiple destinations must be configured:\nswitch(config)#show monitor session\n\nSession s1\n------------------------\n\nSources:\n\nBoth Interfaces:        Et1/1\n\nDestination Ports:\n\n    Et9/1 :  active\n    Et10/1 :  active\n\nIn the above example two destinations, Et9/1 and Et10/1, are configured.\n\nMirroring config must be added with mirror destination being ethernet port, example:\nswitch # show running-config | section monitor\nmonitor session APCON destination Ethernet54/1\n\nIn the above example the argument after destination is an Ethernet port.\n",
          "title": "829136: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "first_fixed": [
          "CSAFPID-13",
          "CSAFPID-14",
          "CSAFPID-15",
          "CSAFPID-16",
          "CSAFPID-17",
          "CSAFPID-18",
          "CSAFPID-19",
          "CSAFPID-20",
          "CSAFPID-21",
          "CSAFPID-22",
          "CSAFPID-23",
          "CSAFPID-24",
          "CSAFPID-25",
          "CSAFPID-26"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE URL",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3646"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.28.6",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.29.2",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.28.2",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "mitigation",
          "details": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades\n\nCVE-2023-3646 has been fixed in the following releases:\n4.28.6M and later releases in the 4.28.x train\n4.29.2F and later releases in the 4.29.x train\nHotfix\nThe following hotfix can be applied to remediate CVE-2023-3646. The hotfix only applies to the releases listed below and no other releases. All other versions require upgrading to a release containing the fix (as listed above):\n\n4.28.2F through 4.28.5.1M releases in the 4.28.x train\n4.29.1F and earlier releases in the 4.29.X train\n\nNote: Installing/uninstalling the Hotfix will result in a restart of the SandFapNi agent and an associated reprogramming of the switch chip. This process could result in outages from 5-20 minutes, depending on the number of active ports in the particular system.\n\nTo determine which hotfix to use, run “show version” from the CLI and refer to the “Architecture” Field.\n\nVersion: 1.0\nURL: SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix\nSWIX hash:(SHA512)\n9c01d1bc1d657879e1a1b657a8c0dab090d589efc3f2c64e9cac1ae0356fce14496809893bffb0892b1505f8b4ee25cad0064bd7315ba6737dc5fdb200539f1a\n\nURL: SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix\nSWIX hash:(SHA512)\n98e98c2c34f81df4da3e4068ac9a81191f4c6ef1acab884972d092c79a7495e00d9a25c8713620d3e25b4699f777810a627634eb8078dcbbb19317ed27a9b0d5\n"
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.23.1",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "The suggestion to prevent this issue is to remove any mirroring config\n#show monitor session\nNo sessions created\n\nThis example confirms that the system does not have any mirroring config present which will prevent this issue from occurring.\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades\n\nCVE-2023-3646 has been fixed in the following releases:\n4.28.6M and later releases in the 4.28.x train\n4.29.2F and later releases in the 4.29.x train\nHotfix\nThe following hotfix can be applied to remediate CVE-2023-3646. The hotfix only applies to the releases listed below and no other releases. All other versions require upgrading to a release containing the fix (as listed above):\n\n4.28.2F through 4.28.5.1M releases in the 4.28.x train\n4.29.1F and earlier releases in the 4.29.X train\n\nNote: Installing/uninstalling the Hotfix will result in a restart of the SandFapNi agent and an associated reprogramming of the switch chip. This process could result in outages from 5-20 minutes, depending on the number of active ports in the particular system.\n\nTo determine which hotfix to use, run “show version” from the CLI and refer to the “Architecture” Field.\n\nVersion: 1.0\nURL: SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix\nSWIX hash:(SHA512)\n9c01d1bc1d657879e1a1b657a8c0dab090d589efc3f2c64e9cac1ae0356fce14496809893bffb0892b1505f8b4ee25cad0064bd7315ba6737dc5fdb200539f1a\n\nURL: SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix\nSWIX hash:(SHA512)\n98e98c2c34f81df4da3e4068ac9a81191f4c6ef1acab884972d092c79a7495e00d9a25c8713620d3e25b4699f777810a627634eb8078dcbbb19317ed27a9b0d5 \n"
        },
        {
          "category": "mitigation",
          "details": "Hotfix: SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix, 1.0, Hash: (SHA-512)9c01d1bc1d657879e1a1b657a8c0dab090d589efc3f2c64e9cac1ae0356fce14496809893bffb0892b1505f8b4ee25cad0064bd7315ba6737dc5fdb200539f1a",
          "product_ids": [
            "CSAFPID-5",
            "CSAFPID-4",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-6",
            "CSAFPID-10",
            "CSAFPID-9"
          ],
          "url": "https://www.arista.com/support/advisories-notices/sa-download/?sa=88-SecurityAdvisory88_CVE-2023-3646_Hotfix_i686.swix"
        },
        {
          "category": "mitigation",
          "details": "Hotfix: SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix, 1.0, Hash: (SHA-512)98e98c2c34f81df4da3e4068ac9a81191f4c6ef1acab884972d092c79a7495e00d9a25c8713620d3e25b4699f777810a627634eb8078dcbbb19317ed27a9b0d5",
          "product_ids": [
            "CSAFPID-5",
            "CSAFPID-4",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-6",
            "CSAFPID-10",
            "CSAFPID-9"
          ],
          "url": "https://www.arista.com/support/advisories-notices/sa-download/?sa=88-SecurityAdvisory88_CVE-2023-3646_Hotfix_x86_64.swix"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-3",
            "CSAFPID-1",
            "CSAFPID-2",
            "CSAFPID-0"
          ]
        }
      ],
      "title": "CVE-2023-3646"
    }
  ]
}