VYPR

Security Advisory

by Arista

CVEs (10)

  • CVE-2024-9188HigJan 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Specially constructed queries cause cross platform scripting leaking administrator tokens

  • CVE-2024-9132HigJan 10, 2025
    risk 0.53cvss 8.1epss 0.01

    The administrator is able to configure an insecure captive portal script

  • CVE-2025-54545HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.

  • CVE-2025-6978HigOct 23, 2025
    risk 0.48cvss 7.2epss 0.14

    Diagnostics command injection vulnerability

  • CVE-2024-9131HigJan 10, 2025
    risk 0.47cvss 7.2epss 0.01

    A user with administrator privileges can perform command injection

  • CVE-2024-9133MedJan 10, 2025
    risk 0.43cvss 6.6epss 0.00

    A user with administrator privileges is able to retrieve authentication tokens

  • CVE-2025-54549MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

  • CVE-2025-54548MedOct 29, 2025
    risk 0.28cvss 4.3epss 0.00

    On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)

  • CVE-2026-75945LowSep 14, 2026
    risk 0.17cvss 2.6epss

    A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

  • CVE-2026-75943LowSep 14, 2026
    risk 0.17cvss 2.6epss

    A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.