Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Velocloud Orchestrator CRITICAL 10.0
CVE-2026-16812 KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

Fix: 5.2.3.14 / 6.1.3.4+
Fix from $2,300 2026-07-27
Ng Firewall MEDIUM 6.0
CVE-2026-25620EPSS 10%

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne…

Mitigation only
Fix from $1,600 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25621

A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i…

Mitigation only
Fix from $1,600 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25622EPSS 10%

A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On …

Fix: 17.4.1+
Fix from $1,600 2026-06-05
Ng Firewall MEDIUM 6.0
CVE-2026-25623EPSS 6%

An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati…

Fix: 17.4.1+
Fix from $1,600 2026-06-05
Eos MEDIUM 5.8
CVE-2026-7473 KEV

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G…

Mitigation only
Fix from $1,600 2026-06-05
Ng Firewall CRITICAL 9.6
CVE-2025-2767

Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…

Mitigation only
Fix from $2,300 2025-04-23
Ng Firewall HIGH 8.8
CVE-2024-9188

Specially constructed queries cause cross platform scripting leaking administrator tokens

Fix: 17.2+
Fix from $1,950 2025-01-10
Ng Firewall HIGH 8.3
CVE-2024-9134

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL…

Fix: 17.2+
Fix from $1,950 2025-01-10
Ng Firewall CRITICAL 9.8
CVE-2024-9132

The administrator is able to configure an insecure captive portal script

Fix: after 17.1.1
Fix from $2,300 2025-01-10
Ng Firewall HIGH 7.6
CVE-2024-47518

Specially constructed queries targeting ETM could discover active remote access sessions

Fix: after 17.1.1
Fix from $1,950 2025-01-10
Ng Firewall HIGH 7.6
CVE-2024-47520

A user with advanced report application access rights can perform actions for which they are not authorized

Fix: after 17.1.1
Fix from $1,950 2025-01-10
Ng Firewall HIGH 7.2
CVE-2024-9131

A user with administrator privileges can perform command injection

Fix: after 17.1.1
Fix from $1,950 2025-01-10
Ng Firewall HIGH 7.1
CVE-2024-47519

Backup uploads to ETM subject to man-in-the-middle interception

Fix: after 17.1.1
Fix from $1,950 2025-01-10
Ng Firewall MEDIUM 5.6
CVE-2024-9133

A user with administrator privileges is able to retrieve authentication tokens

Fix: after 17.1.1
Fix from $1,600 2025-01-10
Ng Firewall MEDIUM 6.8
CVE-2024-47517

Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access

Fix: after 17.1.1
Fix from $1,600 2025-01-10
Ng Firewall HIGH 7.8
CVE-2024-12831

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil…

Mitigation only
Fix from $1,950 2024-12-20
Ng Firewall HIGH 7.3
CVE-2024-12830

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2024-12-20
Ng Firewall MEDIUM 6.3
CVE-2024-12832

Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitr…

Mitigation only
Fix from $1,600 2024-12-20
Ng Firewall HIGH 8.8
CVE-2024-12829

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2024-12-20
Ng Firewall HIGH 8.8
CVE-2024-27889EPSS 9%

Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user wi…

Fix: after 17.0
Fix from $1,950 2024-03-04
Mos MEDIUM 6.5
CVE-2023-24547

On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed…

Fix: after 0.39.4
Fix from $1,600 2023-12-06
Eos HIGH 7.5
CVE-2023-3646

On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and …

Fix: 4.29.2f+
Fix from $1,950 2023-08-29
Eos MEDIUM 6.5
CVE-2023-24548

On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware…

Fix: after 4.24.11m
Fix from $1,600 2023-08-29
Cloudvision Portal HIGH 8.1
CVE-2023-24546

On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …

Fix: after 2021.3
Fix from $1,950 2023-06-13
Eos HIGH 7.5
CVE-2023-24510

On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.

Fix: 4.26.10m / 4.27.10m+
Fix from $1,950 2023-06-05
Eos MEDIUM 6.5
CVE-2023-24512

On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…

Fix: 4.26.10m / 4.27.9m+
Fix from $1,600 2023-04-25
Eos HIGH 7.8
CVE-2023-24509

On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with R…

Fix: 4.24.11m / 4.25.10m+
Fix from $1,950 2023-04-13
Cloudeos HIGH 7.5
CVE-2023-24545

On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se…

Fix: 4.26.9m / 4.27.8m+
Fix from $1,950 2023-04-12
Eos HIGH 7.5
CVE-2023-24511

On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may resu…

Fix: 4.26.10m / 4.27.9m+
Fix from $1,950 2023-04-12