Arista
arista
101 CVEs • 323 products
Products (323)
Click to collapseToggle
Products (323)
Click to collapse
CVEs (101)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL )...Show more |
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI. |
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being fo...Show more |
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device. |
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more |
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more |
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying o...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Ope...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This is...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not hav...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affect...Show more |
1Arista 1Metamako Operating System Jun 17, 2026 Sep 9, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue af...Show more |
4Arista DebianLinux+1 more8C 65 Firmware C 75 FirmwareDebian Linux+5 moreJun 17, 2026 May 11, 2021 N/A· v4 5.4 MEDIUM· v3 3.2 LOW· v2 An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and...Show more |
3Arista SamsungSiemens19C 100 Firmware C 110 FirmwareC 120 Firmware+16 moreJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragm...Show more |
3Arista SamsungSiemens18C 100 Firmware C 110 FirmwareC 120 Firmware+15 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) he...Show more |
3Alfa AristaSiemens6Awus036h Firmware C 65 FirmwareC 75 Firmware+3 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this...Show more |
5Alfa AristaCisco+2 more1941100 4p Firmware 1100 8p Firmware1100 Firmware+191 moreJun 17, 2026 May 11, 2021 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arb...Show more |
5Arista CiscoDebian+2 more1661100 4p Firmware 1100 8p Firmware1100 Firmware+163 moreJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected...Show more |
8Arista CiscoDebian+5 more1811100 4p Firmware 1100 8p Firmware1100 Firmware+178 moreJun 17, 2026 May 11, 2021 N/A· v4 3.5 LOW· v3 2.9 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices...Show more |