VYPR

Eos

by Arista

CVEs (111)

  • CVE-2015-5278MedJan 23, 2020
    risk 0.35cvss 6.5epss 0.02

    The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

  • CVE-2026-73457MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.

  • CVE-2026-73438MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpectedly. The crash…

  • CVE-2026-73463MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may…

  • CVE-2026-19641MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being…

  • CVE-2024-27891MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.

  • CVE-2025-2796MedMay 27, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay…

  • CVE-2024-9135MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.

  • CVE-2024-8000MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants…

  • CVE-2023-24548MedAug 29, 2023
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation…

  • CVE-2026-73445MedSep 16, 2026
    risk 0.32cvss 4.9epss 0.00

    On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect Bootz. This issue was discovered…

  • CVE-2025-8870MedNov 14, 2025
    risk 0.32cvss 4.9epss 0.00

    On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

  • CVE-2026-73443MedSep 16, 2026
    risk 0.31cvss 4.7epss 0.00

    On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed…

  • CVE-2026-73444MedSep 15, 2026
    risk 0.31cvss 4.7epss 0.00

    On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master…

  • CVE-2026-73451MedSep 15, 2026
    risk 0.31cvss 4.8epss 0.00

    On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on…

  • CVE-2025-7048MedJan 6, 2026
    risk 0.28cvss 4.3epss 0.00

    On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

  • CVE-2024-7095MedJan 10, 2025
    risk 0.28cvss 4.3epss 0.00

    On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing…

  • CVE-2026-73440MedSep 16, 2026
    risk 0.27cvss 4.2epss 0.00

    On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who…

  • CVE-2026-19640MedSep 16, 2026
    risk 0.27cvss 4.2epss 0.00

    On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions. This issue was discovered internally…

  • CVE-2025-3456LowAug 25, 2025
    risk 0.25cvss 3.8epss 0.00

    On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be…

Page 5 of 6