VYPR

Vendor CVEs

Arista

All CVEs

189 total · sorted by risk
  • CVE-2020-26140MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

  • CVE-2020-24333MedSep 22, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP server, by accessing a specific API.

  • CVE-2020-3702MedSep 8, 2020
    risk 0.42cvss 6.5epss 0.00

    u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic' in Snapdragon Auto, Snapdragon Compute,…

  • CVE-2019-17596HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2018-14008MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.

  • CVE-2018-12357MedAug 15, 2019
    risk 0.42cvss 6.5epss 0.01

    Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

  • CVE-2018-5255MedMar 5, 2018
    risk 0.42cvss 6.5epss 0.01

    The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.

  • CVE-2026-73467MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

  • CVE-2026-73466MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor…

  • CVE-2026-73465MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious…

  • CVE-2024-12832MedDec 20, 2024
    risk 0.41cvss 6.3epss 0.00

    Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information on affected installations of Arista NG Firewall. Authentication is required to…

  • CVE-2021-28499MedSep 9, 2021
    risk 0.41cvss 6.3epss 0.00

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x…

  • CVE-2026-73460MedSep 16, 2026
    risk 0.40cvss 6.1epss 0.00

    On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart…

  • CVE-2021-28509MedMay 26, 2022
    risk 0.40cvss 6.1epss 0.00

    This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in…

  • CVE-2026-25623MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.06

    An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing…

  • CVE-2026-25622MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.10

    A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logged into the user interface can exploit this input handling behavior to execute…

  • CVE-2026-25621MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.00

    A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

  • CVE-2026-25620MedJun 5, 2026
    risk 0.39cvss 6.0epss 0.10

    An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed.

  • CVE-2026-73469MedSep 16, 2026
    risk 0.38cvss 5.8epss 0.00

    When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and…

  • CVE-2026-73449MedSep 14, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can…

  • CVE-2026-2379MedJun 5, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security…

  • CVE-2023-5502MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.

  • CVE-2025-54549MedOct 29, 2025
    risk 0.38cvss 5.9epss 0.00

    Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

  • CVE-2024-6437MedJan 10, 2025
    risk 0.38cvss 5.8epss 0.01

    On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's…

  • CVE-2023-24547MedDec 6, 2023
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config.…

  • CVE-2023-3646MedAug 29, 2023
    risk 0.38cvss 5.9epss 0.01

    On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.

  • CVE-2021-28511MedAug 5, 2022
    risk 0.38cvss 5.8epss 0.01

    This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could…

  • CVE-2020-26569MedDec 28, 2020
    risk 0.38cvss 5.9epss 0.01

    In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discarded on the receiving VLAN. This affects versions: 4.21.12M…

  • CVE-2019-14810MedOct 10, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on…

  • CVE-2026-25624MedJun 5, 2026
    risk 0.37cvss 5.7epss 0.00

    An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating…

  • CVE-2021-28496MedOct 21, 2021
    risk 0.37cvss 5.7epss 0.00

    On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other…

  • CVE-2021-28507MedJan 14, 2022
    risk 0.36cvss 5.5epss 0.01

    An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

  • CVE-2020-26147MedMay 11, 2021
    risk 0.36cvss 5.4epss 0.08

    An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends…

  • CVE-2015-5239MedJan 23, 2020
    risk 0.36cvss 6.5epss 0.04

    Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

  • CVE-2023-24511MedApr 12, 2023
    risk 0.35cvss 5.3epss 0.01

    On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and…

  • CVE-2021-28510MedJan 26, 2023
    risk 0.35cvss 5.3epss 0.01

    For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.

  • CVE-2020-26146MedMay 11, 2021
    risk 0.35cvss 5.3epss 0.06

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device…

  • CVE-2020-26139MedMay 11, 2021
    risk 0.35cvss 5.3epss 0.06

    An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against…

  • CVE-2020-15898MedDec 28, 2020
    risk 0.35cvss 5.3epss 0.01

    In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traffic (ex. TCP). This affects: EOS 7170 platforms version…

  • CVE-2015-5745MedJan 23, 2020
    risk 0.35cvss 6.5epss 0.03

    Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.

  • CVE-2015-5278MedJan 23, 2020
    risk 0.35cvss 6.5epss 0.02

    The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.

  • CVE-2026-73457MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.

  • CVE-2026-73438MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpectedly. The crash…

  • CVE-2026-73463MedSep 16, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may…

  • CVE-2026-19641MedSep 15, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being…

  • CVE-2024-27891MedJun 4, 2026
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.

  • CVE-2025-54547MedOct 29, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired

  • CVE-2025-2796MedMay 27, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay…

  • CVE-2024-9135MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.

  • CVE-2024-8000MedMar 4, 2025
    risk 0.34cvss 5.3epss 0.00

    On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants…