Arista
arista
101 CVEs • 323 products
Products (323)
Click to collapseToggle
Products (323)
Click to collapse
CVEs (101)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Arista CiscoDebian+3 more1681100 4p Firmware 1100 8p Firmware1100 Firmware+165 moreJun 17, 2026 May 11, 2021 N/A· v4 2.6 LOW· v3 1.8 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse th...Show more |
5Arista DebianIeee+2 more24Ac 1550 Firmware Ac 3165 FirmwareAc 3168 Firmware+21 moreJun 17, 2026 May 11, 2021 N/A· v4 3.5 LOW· v3 2.9 LOW· v2 The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under t...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries c...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of t...Show more |
4Arista DebianFedoraproject+1 more4Debian Linux DnsmasqEos+1 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries....Show more |
An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash, followed by a device reload. The affected Arista EOS versions are: 4.2...Show more |
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to exploitation by unidirectional traffic (ex. UDP) and not bidirectional traff...Show more |
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries. This can result in traffic being discar...Show more |
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the I...Show more |
Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the Controll...Show more |
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads...Show more |
A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Management module to download files not intended for access, located on the CVP...Show more |
3Arista DebianQualcomm13Access Point Apq8053 FirmwareDebian Linux+10 moreJun 17, 2026 Sep 8, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete s...Show more |
A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train, 4.21.3M to 4.21.9M releases in the 4.21.x train, 4.21.3FX-7368.*, 4.2...Show more |
4Arista CanonicalDebian+1 more4Cloudvision Portal Debian LinuxPam Tacplus+1 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. |
An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s EOS VxLAN code, which can allow attackers to crash the VxlanSwFwd agen...Show more |
6Arista DebianFedoraproject+3 more6Communications Performance Intelligence Center Debian LinuxEos+3 moreJun 17, 2026 Mar 6, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. |
1Arista 3Dcs 7050cx3 32s R Firmware Dcs 7050qx 32s R FirmwareDcs 7280sram 48c6 R FirmwareJun 17, 2026 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE:...Show more |
7Arista CanonicalFedoraproject+4 more11Enterprise Linux EosFedora+8 moreNov 21, 2024 Jan 31, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop a...Show more |
3Arista FedoraprojectQemu3Eos FedoraQemuNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. |