Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloudeos HIGH 7.5
CVE-2023-24513

On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by se…

Fix: 4.26.9m / 4.27.8m+
Fix from $1,950 2023-04-12
Eos HIGH 7.5
CVE-2021-28510

For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) cau…

Fix: 4.23.10 / 4.24.8+
Fix from $1,950 2023-01-26
Cloudvision Portal MEDIUM 5.5
CVE-2022-29071

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…

Fix: after 2022.1.0
Fix from $1,600 2022-08-05
Eos MEDIUM 6.5
CVE-2021-28511

This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is th…

Fix: after 4.27.3
Fix from $1,600 2022-08-05
Terminattr MEDIUM 6.1
CVE-2021-28508

This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…

Fix: 1.10.11 / 1.16.8+
Fix from $1,600 2022-05-26
Terminattr MEDIUM 6.1
CVE-2021-28509

This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig trans…

Fix: 1.10.11 / 1.16.8+
Fix from $1,600 2022-05-26
Eos HIGH 7.5
CVE-2021-28505

On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the …

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-14
Eos HIGH 7.5
CVE-2021-28504

On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol…

Fix: 4.26.4m / 4.27.1f+
Fix from $1,950 2022-04-01
Eos CRITICAL 9.8
CVE-2021-28503

The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, whi…

Fix: after 4.26.2
Fix from $2,300 2022-02-04
Eos CRITICAL 9.1
CVE-2021-28506

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially…

Fix: after 4.26.2f
Fix from $2,300 2022-01-14
Eos HIGH 7.8
CVE-2021-28500

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i…

Fix: 4.20+
Fix from $1,950 2022-01-14
Terminattr HIGH 7.8
CVE-2021-28501

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result i…

Fix: after 1.16.2
Fix from $1,950 2022-01-14
Eos HIGH 7.1
CVE-2021-28507

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RE…

Fix: after 4.26.2f
Fix from $1,950 2022-01-14
Eos MEDIUM 6.5
CVE-2021-28496

On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by Bi…

Fix: 4.23.10 / 4.24.8+
Fix from $1,600 2021-10-21
Metamako Operating System CRITICAL 9.8
CVE-2021-28495

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can b…

Fix: 0.32.0+
Fix from $2,300 2021-09-09
Metamako Operating System HIGH 8.8
CVE-2021-28494

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypasse…

Fix: after 0.34.0
Fix from $1,950 2021-09-09
Metamako Operating System HIGH 7.8
CVE-2021-28497

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be a…

Fix: 0.32.0+
Fix from $1,950 2021-09-09
Metamako Operating System HIGH 7.8
CVE-2021-28498

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could resul…

Fix: 0.26.7 / 0.32.0+
Fix from $1,950 2021-09-09
Metamako Operating System MEDIUM 5.5
CVE-2021-28499

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak…

Fix: 0.32.0+
Fix from $1,600 2021-09-09
Metamako Operating System HIGH 7.8
CVE-2021-28493

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to exe…

Fix: after 0.32.0
Fix from $1,950 2021-09-09
Eos HIGH 7.4
CVE-2020-24360

An issue with ARP packets in Arista’s EOS affecting the 7800R3, 7500R3, and 7280R3 series of products may result in issues that cause a kernel crash,…

Fix: after 4.24.2.4f
Fix from $1,950 2020-12-28
Eos MEDIUM 5.3
CVE-2020-15898

In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction. This vulnerability is only susceptible to explo…

Fix: after 4.24.2.1f
Fix from $1,600 2020-12-28
Eos MEDIUM 5.9
CVE-2020-26569

In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly fo…

Fix: after 4.24.2f
Fix from $1,600 2020-12-28
Eos HIGH 7.5
CVE-2020-15897

Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or …

Fix: 4.21.12m / 4.22.7m+
Fix from $1,950 2020-10-26
Cloudvision Exchange HIGH 7.5
CVE-2020-13100

Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote att…

Fix: 4.21.12m / 4.22.7m+
Fix from $1,950 2020-10-26
Eos HIGH 7.5
CVE-2020-17355

Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of serv…

Fix: 4.21.12m / 4.22.7m+
Fix from $1,950 2020-10-21
Cloudvision Portal MEDIUM 6.5
CVE-2020-24333

A vulnerability in Arista’s CloudVision Portal (CVP) prior to 2020.2 allows users with “read-only” or greater access rights to the Configlet Manageme…

Fix: 2020.2.0+
Fix from $1,600 2020-09-22
Velocloud Orchestrator HIGH 8.8
CVE-2020-3973

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velo…

Fix: 3.3.2+
Fix from $1,950 2020-07-08
Cloudeos HIGH 7.5
CVE-2020-11622

A vulnerability exists in Arista’s Cloud EOS VM / vEOS 4.23.2M and below releases in the 4.23.x train, 4.22.4M and below releases in the 4.22.x train…

Fix: after 4.23.2m
Fix from $1,950 2020-06-10
Eos HIGH 7.5
CVE-2019-18948

An issue was found in Arista EOS. Specific malformed ARP packets can impact the software forwarding of VxLAN packets. This issue is found in Arista’s…

Fix: after 4.23.1f
Fix from $1,950 2020-04-16