← Back

Arista

arista

101 CVEs • 323 products

Products (323)

Click to collapse
Toggle
Eos
eos
Ng Firewall
ng_firewall
C 65 Firmware
c-65_firmware
C 75 Firmware
c-75_firmware
O 90 Firmware
o-90_firmware
W 68 Firmware
w-68_firmware
Terminattr
terminattr
Cloudeos
cloudeos
Mos
mos
Veos
veos
Access Point
access_point
Ceos Lab
ceos-lab
Veos Lab
veos-lab
Multiaccess
multiaccess
Velocloud Edge
velocloud_edge
Netvisor Os
netvisor_os
Dcs 7050t
dcs-7050t
Dcs 7050q
dcs-7050q
Dcs 7050s
dcs-7050s
7020r
7280e
7280r
7280r2
7280r3
7500e
7500r
7500r2
7500r3
Av2
av2
C 75
c-75
C75 E
c75-e
O 90
o-90
O90e
o90e
W 68
w-68
7010t 48
7010t-48
7050cx3 32s
7050cx3-32s
7050cx3m 32s
7050cx3m-32s
7050qx 32s
7050qx-32s
7050qx2 32s
7050qx2-32s
7050sx 128
7050sx-128
7050sx 64
7050sx-64
7050sx 72q
7050sx-72q
7050sx2 128
7050sx2-128
7050sx2 72q
7050sx2-72q
7050sx3 48c8
7050sx3-48c8
7050sx3 48yc
7050sx3-48yc
7050sx3 48yc8
7050sx3-48yc8
7050sx3 96yc8
7050sx3-96yc8
7050tx 48
7050tx-48
7050tx 64
7050tx-64
7050tx 72q
7050tx-72q
7050tx2 128
7050tx2-128
7050tx3 48c8
7050tx3-48c8
7060cx 32s
7060cx-32s
7060cx2 32s
7060cx2-32s
7060dx4 32
7060dx4-32
7060px4 32
7060px4-32
7060sx2 48yc6
7060sx2-48yc6
720xp 24y6
720xp-24y6
720xp 24zy4
720xp-24zy4
720xp 48y6
720xp-48y6
720xp 48zc2
720xp-48zc2
720xp 96zc2
720xp-96zc2
7250qx 64
7250qx-64
7260cx
7260cx3
7260cx3 64
7260cx3-64
7260qx
7300x 32q
7300x-32q
7300x 64s
7300x-64s
7300x 64t
7300x-64t
7300x3 32c
7300x3-32c
7300x3 48yc4
7300x3-48yc4

CVEs (101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arista
1Ng Firewall
Jun 17, 2026
Dec 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authenticati...Show more
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to exploit this vulnerability. The specific flaw exists within the ExecManagerImpl class. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-24015.Show less
13Almalinux
AmazonApple+10 more
53500f Firmware
8300 Firmware8700 Firmware+50 more
Jun 17, 2026
Jul 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able t...Show more
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.Show less
1Arista
1Ng Firewall
Jun 17, 2026
Mar 4, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL inject...Show more
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. Show less
1Arista
1Multiaccess
Jun 17, 2026
Mar 4, 2024
N/A· v4
3.1 LOW· v3
N/A· v2
On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that shoul...Show more
On affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and someShow less
1Arista
1Mos
Jun 17, 2026
Dec 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as wel...Show more
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config. Show less
1Arista
1Eos
Jun 17, 2026
Aug 29, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.
1Arista
1Eos
Jun 17, 2026
Aug 29, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device wil...Show more
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place. Show less
1Arista
1Cloudvision Portal
Jun 17, 2026
Jun 13, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry a...Show more
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision Portal product when run on-premise. It does not impact CloudVision as-a-Service.Show less
1Arista
1Eos
Jun 17, 2026
Jun 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
1Arista
4Ceos Lab
CloudeosEos+1 more
Jun 17, 2026
Apr 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only wh...Show more
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVisionShow less
1Arista
1Eos
Jun 17, 2026
Apr 13, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby super...Show more
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.Show less
1Arista
1Cloudeos
Jun 17, 2026
Apr 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buf...Show more
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.Show less
1Arista
1Eos
Jun 17, 2026
Apr 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to t...Show more
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.Show less
1Arista
1Cloudeos
Jun 17, 2026
Apr 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buf...Show more
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.Show less
1Arista
1Eos
Jun 17, 2026
Jan 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will mak...Show more
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.Show less
1Arista
1Cloudvision Portal
Jun 17, 2026
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and Syst...Show more
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users.Show less
1Arista
1Eos
Jun 17, 2026
Aug 5, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filte...Show more
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed by a NAT ACL and a range denied by a Security ACL to be forwarded incorrectly as it should have been denied by the Security ACL. This can enable an ACL bypass.Show less
1Arista
2Eos
Terminattr
Jun 17, 2026
May 26, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain co...Show more
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traffic to be decrypted or modified by other authorized users on the device.Show less
1Arista
2Eos
Terminattr
Jun 17, 2026
May 26, 2022
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain co...Show more
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized users, which could cause IPsec traffic to be decrypted or modified by other authorized users on the device.Show less
1Arista
1Eos
Jun 17, 2026
Apr 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the...Show more
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.Show less