← Back

Arista

arista

101 CVEs • 323 products

Products (323)

Click to collapse
Toggle
Eos
eos
Ng Firewall
ng_firewall
C 65 Firmware
c-65_firmware
C 75 Firmware
c-75_firmware
O 90 Firmware
o-90_firmware
W 68 Firmware
w-68_firmware
Terminattr
terminattr
Cloudeos
cloudeos
Mos
mos
Veos
veos
Access Point
access_point
Ceos Lab
ceos-lab
Veos Lab
veos-lab
Multiaccess
multiaccess
Velocloud Edge
velocloud_edge
Netvisor Os
netvisor_os
Dcs 7050t
dcs-7050t
Dcs 7050q
dcs-7050q
Dcs 7050s
dcs-7050s
7020r
7280e
7280r
7280r2
7280r3
7500e
7500r
7500r2
7500r3
Av2
av2
C 75
c-75
C75 E
c75-e
O 90
o-90
O90e
o90e
W 68
w-68
7010t 48
7010t-48
7050cx3 32s
7050cx3-32s
7050cx3m 32s
7050cx3m-32s
7050qx 32s
7050qx-32s
7050qx2 32s
7050qx2-32s
7050sx 128
7050sx-128
7050sx 64
7050sx-64
7050sx 72q
7050sx-72q
7050sx2 128
7050sx2-128
7050sx2 72q
7050sx2-72q
7050sx3 48c8
7050sx3-48c8
7050sx3 48yc
7050sx3-48yc
7050sx3 48yc8
7050sx3-48yc8
7050sx3 96yc8
7050sx3-96yc8
7050tx 48
7050tx-48
7050tx 64
7050tx-64
7050tx 72q
7050tx-72q
7050tx2 128
7050tx2-128
7050tx3 48c8
7050tx3-48c8
7060cx 32s
7060cx-32s
7060cx2 32s
7060cx2-32s
7060dx4 32
7060dx4-32
7060px4 32
7060px4-32
7060sx2 48yc6
7060sx2-48yc6
720xp 24y6
720xp-24y6
720xp 24zy4
720xp-24zy4
720xp 48y6
720xp-48y6
720xp 48zc2
720xp-48zc2
720xp 96zc2
720xp-96zc2
7250qx 64
7250qx-64
7260cx
7260cx3
7260cx3 64
7260cx3-64
7260qx
7300x 32q
7300x-32q
7300x 64s
7300x-64s
7300x 64t
7300x-64t
7300x3 32c
7300x3-32c
7300x3 48yc4
7300x3-48yc4

CVEs (101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arista
1Eos
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL )...Show more
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.Show less
1Arista
1Eos
Jun 17, 2026
Feb 4, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.1 HIGH· v3
4.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being fo...Show more
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
1Arista
1Terminattr
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.Show less
1Arista
1Eos
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword con...Show more
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.Show less
1Arista
1Eos
Jun 17, 2026
Oct 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying o...Show more
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Ope...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This is...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and prior releases in the MOS-0.2x train MOS-0.31.1 and prior releases in the MOS-0.3x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not hav...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post releases in the MOS-0.1x train MOS-0.26.6 and below releases in the MOS-0.2x train MOS-0.31.1 and below releases in the MOS-0.3x trainShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affect...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releasesShow less
1Arista
1Metamako Operating System
Jun 17, 2026
Sep 9, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue af...Show more
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releasesShow less
4Arista
DebianLinux+1 more
8C 65 Firmware
C 75 FirmwareDebian Linux+5 more
Jun 17, 2026
May 11, 2021
N/A· v4
5.4 MEDIUM· v3
3.2 LOW· v2
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and...Show more
An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used.Show less
3Arista
SamsungSiemens
19C 100 Firmware
C 110 FirmwareC 120 Firmware+16 more
Jun 17, 2026
May 11, 2021
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragm...Show more
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.Show less
3Arista
SamsungSiemens
18C 100 Firmware
C 110 FirmwareC 120 Firmware+15 more
Jun 17, 2026
May 11, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) he...Show more
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.Show less
3Alfa
AristaSiemens
6Awus036h Firmware
C 65 FirmwareC 75 Firmware+3 more
Jun 17, 2026
May 11, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this...Show more
An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.Show less
5Alfa
AristaCisco+2 more
1941100 4p Firmware
1100 8p Firmware1100 Firmware+191 more
Jun 17, 2026
May 11, 2021
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arb...Show more
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.Show less
5Arista
CiscoDebian+2 more
1661100 4p Firmware
1100 8p Firmware1100 Firmware+163 more
Jun 17, 2026
May 11, 2021
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected...Show more
An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.Show less
8Arista
CiscoDebian+5 more
1811100 4p Firmware
1100 8p Firmware1100 Firmware+178 more
Jun 17, 2026
May 11, 2021
N/A· v4
3.5 LOW· v3
2.9 LOW· v2
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices...Show more
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.Show less