VYPR

Vendor CVEs

Arista

All CVEs

190 total · sorted by risk
  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2026-93952CriKEVSep 22, 2026
    risk 0.77cvss 10.0epss 0.01

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator…

  • CVE-2017-14491CriOct 4, 2017
    risk 0.73cvss 9.8epss 0.85

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

  • CVE-2020-10188CriMar 6, 2020
    risk 0.70cvss 9.8epss 0.74

    utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

  • CVE-2020-9015CriFeb 20, 2020
    risk 0.68cvss 9.8epss 0.16

    Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue…

  • CVE-2017-18017CriJan 3, 2018
    risk 0.68cvss 9.8epss 0.53

    The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the…

  • CVE-2026-31431HigKEVApr 22, 2026
    risk 0.67cvss 7.8epss 0.03

    In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the…

  • CVE-2026-73456CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.01

    Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control…

  • CVE-2026-73453CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.01

    An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By…

  • CVE-2025-0505CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.01

    On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under…

  • CVE-2024-11186CriMay 8, 2025
    risk 0.65cvss 10.0epss 0.01

    On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact…

  • CVE-2024-6387HigJul 1, 2024
    risk 0.64cvss 8.1epss 1.00

    A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time…

  • CVE-2024-27890CriJun 4, 2026
    risk 0.63cvss 9.6epss 0.04

    Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

  • CVE-2026-86106CriSep 16, 2026
    risk 0.62cvss 9.6epss 0.00

    An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.

  • CVE-2026-73437CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent…

  • CVE-2024-27892CriJun 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.

  • CVE-2025-2767CriApr 23, 2025
    risk 0.62cvss 9.6epss 0.01

    Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The…

  • CVE-2021-28494CriSep 9, 2021
    risk 0.62cvss 9.6epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior…

  • CVE-2023-24509CriApr 13, 2023
    risk 0.60cvss 9.3epss 0.00

    On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation.…

  • CVE-2026-73447CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges…

  • CVE-2024-12378CriMay 8, 2025
    risk 0.59cvss 9.1epss 0.01

    On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.

  • CVE-2025-1260CriMar 4, 2025
    risk 0.59cvss 9.1epss 0.00

    On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.

  • CVE-2021-28506CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.

  • CVE-2021-28501CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

  • CVE-2021-28500CriJan 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

  • CVE-2024-27889HigMar 4, 2024
    risk 0.58cvss 8.8epss 0.09

    Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying…

  • CVE-2026-73464HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the…

  • CVE-2025-6979HigOct 23, 2025
    risk 0.57cvss 8.8epss 0.01

    Captive Portal can allow authentication bypass

  • CVE-2024-8100HigMay 8, 2025
    risk 0.57cvss 8.7epss 0.01

    On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision.

  • CVE-2024-9188HigJan 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Specially constructed queries cause cross platform scripting leaking administrator tokens

  • CVE-2024-12829HigDec 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2023-24512HigApr 25, 2023
    risk 0.57cvss 8.8epss 0.01

    On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the…

  • CVE-2021-28498HigSep 9, 2021
    risk 0.57cvss 8.7epss 0.00

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and…

  • CVE-2020-3973HigJul 8, 2020
    risk 0.57cvss 8.8epss 0.01

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not privileged.

  • CVE-2016-9012HigJan 23, 2017
    risk 0.57cvss 8.8epss 0.02

    CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.

  • CVE-2024-4578HigJun 27, 2024
    risk 0.55cvss 8.4epss 0.00

    This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. The SSH CLI session does not require…

  • CVE-2021-28493HigSep 9, 2021
    risk 0.55cvss 8.4epss 0.00

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the…

  • CVE-2025-5088HigJun 5, 2026
    risk 0.54cvss 8.3epss 0.00

    An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication,…

  • CVE-2024-9134HigJan 10, 2025
    risk 0.54cvss 8.3epss 0.01

    Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.

  • CVE-2024-47519HigJan 10, 2025
    risk 0.54cvss 8.3epss 0.00

    Backup uploads to ETM subject to man-in-the-middle interception

  • CVE-2026-73435HigSep 16, 2026
    risk 0.53cvss 8.2epss 0.00

    On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet…

  • CVE-2026-73454HigSep 16, 2026
    risk 0.53cvss 8.1epss 0.00

    On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or…

  • CVE-2026-73458HigSep 15, 2026
    risk 0.53cvss 8.2epss 0.00

    On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor…

  • CVE-2024-9132HigJan 10, 2025
    risk 0.53cvss 8.1epss 0.01

    The administrator is able to configure an insecure captive portal script

  • CVE-2023-24546HigJun 13, 2023
    risk 0.53cvss 8.1epss 0.00

    On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This…

  • CVE-2026-73461HigSep 16, 2026
    risk 0.52cvss 8.0epss 0.00

    On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig…

  • CVE-2026-86108HigSep 16, 2026
    risk 0.52cvss 8.0epss 0.01

    Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitation may allow command…

  • CVE-2025-54545HigOct 29, 2025
    risk 0.51cvss 7.8epss 0.00

    On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.

  • CVE-2024-12831HigDec 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An attacker must first obtain the ability to execute low-privileged code on…

Page 1 of 4