VYPR

Vendor CVEs

Arista

All CVEs

146 total · sorted by risk
  • CVE-2020-15897HigOct 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.

  • CVE-2020-13100HigOct 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.

  • CVE-2020-17355HigOct 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.

  • CVE-2020-11622HigJun 10, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.21.4-FCRFX.*, 4.21.4.1, 4.21.7.1, 4.22.2.0.1, 4.22.2.2.1,…

  • CVE-2019-18948HigApr 16, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agent. This affects EOS 4.21.8M and below releases in the…

  • CVE-2018-5254HigApr 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.

  • CVE-2016-6894HigJan 4, 2017
    risk 0.49cvss 7.5epss 0.02

    Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.

  • CVE-2015-6855HigNov 6, 2015
    risk 0.49cvss 7.5epss 0.04

    hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty…

  • CVE-2025-6978HigOct 23, 2025
    risk 0.48cvss 7.2epss 0.14

    Diagnostics command injection vulnerability

  • CVE-2024-12830HigDec 20, 2024
    risk 0.48cvss 7.3epss 0.01

    Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is not required to exploit this vulnerability. The…

  • CVE-2021-28503HigFeb 4, 2022
    risk 0.48cvss 7.4epss 0.01

    The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.

  • CVE-2020-24360HigDec 28, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.24.2.4F and below releases in the 4.24.x train; 4.23.4M…

  • CVE-2024-9131HigJan 10, 2025
    risk 0.47cvss 7.2epss 0.01

    A user with administrator privileges can perform command injection

  • CVE-2021-28495HigSep 9, 2021
    risk 0.47cvss 7.2epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in…

  • CVE-2024-47517MedJan 10, 2025
    risk 0.44cvss 6.8epss 0.00

    Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

  • CVE-2021-28508MedMay 26, 2022
    risk 0.44cvss 6.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in…

  • CVE-2024-9133MedJan 10, 2025
    risk 0.43cvss 6.6epss 0.00

    A user with administrator privileges is able to retrieve authentication tokens

  • CVE-2020-26144MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.05

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject…

  • CVE-2020-26143MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.04

    An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network…

  • CVE-2025-5090MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a…

  • CVE-2025-5089MedJun 5, 2026
    risk 0.42cvss 6.5epss 0.00

    In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either…

  • CVE-2024-6858MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.

  • CVE-2025-8872MedDec 16, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue…

  • CVE-2024-11185MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

  • CVE-2025-0936MedMay 7, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote…

  • CVE-2024-47518MedJan 10, 2025
    risk 0.42cvss 6.4epss 0.00

    Specially constructed queries targeting ETM could discover active remote access sessions

  • CVE-2024-5872MedJan 10, 2025
    risk 0.42cvss 6.5epss 0.00

    On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.

  • CVE-2023-24513MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the…

  • CVE-2020-26140MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

  • CVE-2020-24333MedSep 22, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

  • CVE-2020-3702MedSep 8, 2020
    risk 0.42cvss 6.5epss 0.00

    u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute,…

  • CVE-2019-17596HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2018-14008MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

  • CVE-2018-12357MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

  • CVE-2018-5255MedMar 5, 2018
    risk 0.42cvss 6.5epss 0.01

    The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.

  • CVE-2024-12832MedDec 20, 2024
    risk 0.41cvss 6.3epss 0.00

    Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authentication is required to…

  • CVE-2021-28499MedSep 9, 2021
    risk 0.41cvss 6.3epss 0.00

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x…

  • CVE-2021-28509MedMay 26, 2022
    risk 0.40cvss 6.1epss 0.00

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in…

  • CVE-2026-25623MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.06

    An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing…

  • CVE-2026-25622MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.10

    A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute…

  • CVE-2026-25621MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.00

    A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

  • CVE-2026-25620MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.10

    An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

  • CVE-2026-2379MedJun 5, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security…

  • CVE-2023-5502MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

  • CVE-2025-54549MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

  • CVE-2024-6437MedJan 10, 2025
    risk 0.38cvss 5.8epss 0.01

    On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's…

  • CVE-2023-24547MedDec 6, 2023
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.…

  • CVE-2023-3646MedAug 29, 2023
    risk 0.38cvss 5.9epss 0.01

    On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.

  • CVE-2021-28511MedAug 5, 2022
    risk 0.38cvss 5.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could…

  • CVE-2020-26569MedDec 28, 2020
    risk 0.38cvss 5.9epss 0.01

    In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M…