VYPR

Eos

by Arista

CVEs (75)

  • CVE-2021-28505HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.

  • CVE-2021-28504HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

  • CVE-2020-15897HigOct 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.

  • CVE-2020-17355HigOct 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.

  • CVE-2019-18948HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the…

  • CVE-2018-5254HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

  • CVE-2016-6894HigJan 4, 2017
    risk 0.49cvss 7.5epss 0.02

    Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.

  • CVE-2015-6855HigNov 6, 2015
    risk 0.49cvss 7.5epss 0.04

    hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty…

  • CVE-2021-28503HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

  • CVE-2020-24360HigDec 28, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M…

  • CVE-2021-28508MedMay 26, 2022
    risk 0.44cvss 6.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in…

  • CVE-2025-5089MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either…

  • CVE-2024-6858MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.

  • CVE-2025-8872MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue…

  • CVE-2024-11185MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

  • CVE-2025-0936MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote…

  • CVE-2024-5872MedJan 10, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.

  • CVE-2019-17596HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2018-14008MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

  • CVE-2018-5255MedMar 5, 2018
    risk 0.42cvss 6.5epss 0.01

    The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.