ARST-ND-000860 - The Arista network device must be running an operating system release that is currently supported by the vendor.

Information

Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Upgrade the Arista network device to an operating system that is supported by the vendor.

Step 1: The Administrator would log on to www.arista.com/support/software-download website and choose EOS/Active Releases and choose appropriate version of EOS to download.

Step 2: Transfer the EOS-4.x.yz.swi.sha512sum to Arista network device directory 'flash:'.

Step 3: From the EOS CLI, type dir flash: to verify the file EOS-4.x.yz.swi.sha512sum is in the directory 'flash:'.

switch#directory flash:
EOS-4.x.yz.swi.sha512sum

Step 4: Use the command verify to verify the checksum sha512sum:

switch#verify flash: /sha512 flash:EOS-4.x.yz
checksum should match

Step 5: The file can also be verified from bash.

switch#bash
#bash
# sha512sum /mnt/flash/EOS-4.x.yz
*note the Arista network device would not run an invalid version of EOS and if the checksum does not match, contact an Arista Representative for assistance.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Arista_MLS_EOS_4-2x_Y23M02_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|I, CCI|CCI-000366, Rule-ID|SV-255967r882243_rule, STIG-ID|ARST-ND-000860, Vuln-ID|V-255967

Plugin: Arista

Control ID: 0fd4d41d3eda210fd6e29e8260189a52bb8b8ffd6a0d52d6f9cd58ebb34d3159