VYPR

Vendor CVEs

Arista

All CVEs

189 total · sorted by risk
  • CVE-2025-1259HigMar 4, 2025
    risk 0.50cvss 7.7epss 0.00

    On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available

  • CVE-2026-73455HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.

  • CVE-2026-73439HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule…

  • CVE-2025-8873HigJun 4, 2026
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not…

  • CVE-2025-54546HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms, restricted users could use SSH port forwarding to access host-internal services

  • CVE-2025-6980HigOct 23, 2025
    risk 0.49cvss 7.5epss 0.00

    Captive Portal can expose sensitive information

  • CVE-2025-6188HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of…

  • CVE-2024-9448HigMay 8, 2025
    risk 0.49cvss 7.5epss 0.01

    On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be…

  • CVE-2024-47520HigJan 10, 2025
    risk 0.49cvss 7.6epss 0.00

    A user with advanced report application access rights can perform actions for which they are not authorized

  • CVE-2023-24510HigJun 5, 2023
    risk 0.49cvss 7.5epss 0.01

    On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.

  • CVE-2023-24545HigApr 12, 2023
    risk 0.49cvss 7.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…

  • CVE-2021-28505HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.

  • CVE-2021-28504HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

  • CVE-2020-15897HigOct 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.

  • CVE-2020-13100HigOct 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.

  • CVE-2020-17355HigOct 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.

  • CVE-2020-11622HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.21.4-FCRFX.*, 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1,…

  • CVE-2019-18948HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the…

  • CVE-2018-5254HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

  • CVE-2016-6894HigJan 4, 2017
    risk 0.49cvss 7.5epss 0.02

    Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.

  • CVE-2015-6855HigNov 6, 2015
    risk 0.49cvss 7.5epss 0.04

    hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty…

  • CVE-2026-2380HigSep 16, 2026
    risk 0.48cvss 7.4epss 0.00

    On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that…

  • CVE-2026-73459HigSep 16, 2026
    risk 0.48cvss 7.4epss 0.00

    On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.

  • CVE-2026-73446HigSep 16, 2026
    risk 0.48cvss 7.4epss 0.00

    On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption…

  • CVE-2025-6978HigOct 23, 2025
    risk 0.48cvss 7.2epss 0.14

    Diagnostics command injection vulnerability

  • CVE-2024-12830HigDec 20, 2024
    risk 0.48cvss 7.3epss 0.01

    Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-28503HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

  • CVE-2020-24360HigDec 28, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M…

  • CVE-2024-9131HigJan 10, 2025
    risk 0.47cvss 7.2epss 0.01

    A user with administrator privileges can perform command injection

  • CVE-2021-28495HigSep 9, 2021
    risk 0.47cvss 7.2epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in…

  • CVE-2026-73450MedSep 16, 2026
    risk 0.45cvss 6.9epss 0.00

    On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch…

  • CVE-2024-47517MedJan 10, 2025
    risk 0.44cvss 6.8epss 0.00

    Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

  • CVE-2021-28508MedMay 26, 2022
    risk 0.44cvss 6.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in…

  • CVE-2024-9133MedJan 10, 2025
    risk 0.43cvss 6.6epss 0.00

    A user with administrator privileges is able to retrieve authentication tokens

  • CVE-2020-26144MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.05

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject…

  • CVE-2020-26143MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.04

    An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network…

  • CVE-2026-73462MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to…

  • CVE-2026-77190MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent…

  • CVE-2026-73468MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

  • CVE-2026-73436MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.

  • CVE-2026-19655MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthenticated attacker…

  • CVE-2025-5090MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a…

  • CVE-2025-5089MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either…

  • CVE-2024-6858MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.

  • CVE-2025-8872MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue…

  • CVE-2024-11185MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

  • CVE-2025-0936MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote…

  • CVE-2024-47518MedJan 10, 2025
    risk 0.42cvss 6.4epss 0.00

    Specially constructed queries targeting ETM could discover active remote access sessions

  • CVE-2024-5872MedJan 10, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.

  • CVE-2023-24513MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…