← Back

Arista

arista

101 CVEs • 323 products

Products (323)

Click to collapse
Toggle
Eos
eos
Ng Firewall
ng_firewall
C 65 Firmware
c-65_firmware
C 75 Firmware
c-75_firmware
O 90 Firmware
o-90_firmware
W 68 Firmware
w-68_firmware
Terminattr
terminattr
Cloudeos
cloudeos
Mos
mos
Veos
veos
Access Point
access_point
Ceos Lab
ceos-lab
Veos Lab
veos-lab
Multiaccess
multiaccess
Velocloud Edge
velocloud_edge
Netvisor Os
netvisor_os
Dcs 7050t
dcs-7050t
Dcs 7050q
dcs-7050q
Dcs 7050s
dcs-7050s
7020r
7280e
7280r
7280r2
7280r3
7500e
7500r
7500r2
7500r3
Av2
av2
C 75
c-75
C75 E
c75-e
O 90
o-90
O90e
o90e
W 68
w-68
7010t 48
7010t-48
7050cx3 32s
7050cx3-32s
7050cx3m 32s
7050cx3m-32s
7050qx 32s
7050qx-32s
7050qx2 32s
7050qx2-32s
7050sx 128
7050sx-128
7050sx 64
7050sx-64
7050sx 72q
7050sx-72q
7050sx2 128
7050sx2-128
7050sx2 72q
7050sx2-72q
7050sx3 48c8
7050sx3-48c8
7050sx3 48yc
7050sx3-48yc
7050sx3 48yc8
7050sx3-48yc8
7050sx3 96yc8
7050sx3-96yc8
7050tx 48
7050tx-48
7050tx 64
7050tx-64
7050tx 72q
7050tx-72q
7050tx2 128
7050tx2-128
7050tx3 48c8
7050tx3-48c8
7060cx 32s
7060cx-32s
7060cx2 32s
7060cx2-32s
7060dx4 32
7060dx4-32
7060px4 32
7060px4-32
7060sx2 48yc6
7060sx2-48yc6
720xp 24y6
720xp-24y6
720xp 24zy4
720xp-24zy4
720xp 48y6
720xp-48y6
720xp 48zc2
720xp-48zc2
720xp 96zc2
720xp-96zc2
7250qx 64
7250qx-64
7260cx
7260cx3
7260cx3 64
7260cx3-64
7260qx
7300x 32q
7300x-32q
7300x 64s
7300x-64s
7300x 64t
7300x-64t
7300x3 32c
7300x3-32c
7300x3 48yc4
7300x3-48yc4

CVEs (101)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Arista
CanonicalFedoraproject+1 more
4Eos
FedoraQemu+1 more
Nov 21, 2024
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving p...Show more
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.Show less
5Arista
CanonicalFedoraproject+2 more
8Eos
FedoraLinux Enterprise Debuginfo+5 more
Nov 21, 2024
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
1Arista
1Cloudvision Portal
Jun 17, 2026
Dec 19, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. T...Show more
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions that are otherwise restricted in the GUI.Show less
1Arista
1Cloudvision Portal
Jun 17, 2026
Dec 19, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.Show less
6Arista
DebianFedoraproject+3 more
11Cloudvision Portal
Debian LinuxDeveloper Tools+8 more
Jun 17, 2026
Oct 24, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that veri...Show more
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.Show less
1Arista
1Extensible Operating System
Jun 17, 2026
Oct 10, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing...Show more
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially leading to an Out of Memory (OOM) condition that is disruptive to traffic forwarding. Affected EOS versions include: 4.22 release train: 4.22.1F and earlier releases 4.21 release train: 4.21.0F - 4.21.2.3F, 4.21.3F - 4.21.7.1M 4.20 release train: 4.20.14M and earlier releases 4.19 release train: 4.19.12M and earlier releases End of support release trains (4.18 and 4.17)Show less
1Arista
1Eos
Nov 21, 2024
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
1Arista
1Cloudvision Portal
Nov 21, 2024
Aug 15, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
1Arista
1Eos
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
1Arista
1Eos
Nov 21, 2024
Mar 5, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
9Arista
CanonicalDebian+6 more
29Arx
Caas PlatformCloud Magnum Orchestration+26 more
Jan 3, 2025
Jan 3, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or poss...Show more
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.Show less
12Arista
ArubanetworksCanonical+9 more
21Arubaos
Debian LinuxDiskstation Manager+18 more
May 13, 2026
Oct 4, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
1Arista
1Cloudvision Portal
May 13, 2026
Jan 23, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
1Arista
3Dcs 7050q Eos Software
Dcs 7050s Eos SoftwareDcs 7050t Eos Software
May 6, 2026
Jan 4, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.
1Arista
1Eos
May 6, 2026
Nov 19, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, a...Show more
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.Show less
6Arista
CanonicalDebian+3 more
7Debian Linux
EosFedora+4 more
May 6, 2026
Nov 6, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demo...Show more
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.Show less
6Arista
DebianLenovo+3 more
19Debian Linux
Emc Px12 400r IvxEmc Px12 450r Ivx+16 more
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host O...Show more
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.Show less
7Arista
DebianFedoraproject+4 more
24Debian Linux
Enterprise Linux Compute Node EusEnterprise Linux Desktop+21 more
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
8Arista
CanonicalDebian+5 more
18Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+15 more
May 6, 2026
Jun 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
17Apple
AristaCanonical+14 more
74Arx Firmware
BashBig Ip Access Policy Manager+71 more
Apr 22, 2026
Sep 25, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown oth...Show more
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.Show less