VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Ne…
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure i…
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On …
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generati…
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (G…
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitra…
Specially constructed queries cause cross platform scripting leaking administrator tokens
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL…
The administrator is able to configure an insecure captive portal script
Specially constructed queries targeting ETM could discover active remote access sessions
A user with advanced report application access rights can perform actions for which they are not authorized
A user with administrator privileges can perform command injection
Backup uploads to ETM subject to man-in-the-middle interception
A user with administrator privileges is able to retrieve authentication tokens
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil…
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…
Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitr…
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user wi…
On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed…
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and …
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware…
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor …
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to updat…
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with R…
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se…
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may resu…