Medium severity6.5NVD Advisory· Published Jun 5, 2026· Updated Jun 5, 2026
CVE-2025-5090
CVE-2025-5090
Description
CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access to the connected switch to be able to send custom TCP packets to the CVX.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
1- Arista EOS: Eleven Network Device Vulnerabilities Disclosed TogetherVypr Intelligence · Jun 5, 2026