Arista Eos vulnerabilities
44 known vulnerabilities affecting arista/eos.
Total CVEs
44
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH17MEDIUM14LOW4
Vulnerabilities
Page 1 of 3
CVE-2014-6271P1CRITICALCVSS 9.8KEVPoC≥ 4.9.0, < 4.9.12≥ 4.10.0, < 4.10.9+4 more2014-09-24
CVE-2014-6271 [CRITICAL] CWE-78 CVE-2014-6271: GNU Bash through 4.3 processes trailing strings after function definitions in the values of environm
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts execute
nvd
CVE-2014-7169P1CRITICALCVSS 9.8KEVPoC≥ 4.9.0, < 4.9.12≥ 4.10.0, < 4.10.9+4 more2014-09-25
CVE-2014-7169 [CRITICAL] CVE-2014-7169: GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definiti
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgi
nvd
CVE-2024-6387P1HIGHCVSS 8.1ExploitedPoC≥ 4.32.0, ≤ 4.32.1f2024-07-01
CVE-2024-6387 [HIGH] CWE-364 CVE-2024-6387: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race con
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
nvd
CVE-2017-14491P1CRITICALCVSS 9.8PoC≤ 4.15≥ 4.16, < 4.16.13m+2 more2017-10-04
CVE-2017-14491 [CRITICAL] CWE-787 CVE-2017-14491: Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of servi
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
nvd
CVE-2020-10188P2CRITICALCVSS 9.8≤ 4.20.15≥ 4.21.0, ≤ 4.21.10m+3 more2020-03-06
CVE-2020-10188 [CRITICAL] CWE-120 CVE-2020-10188: utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.
nvd
CVE-2017-18017P3CRITICALCVSS 9.8v4.20.1fx-virtual-router2018-01-03
CVE-2017-18017 [CRITICAL] CWE-416 CVE-2017-18017: The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
nvd
CVE-2021-28503P2CRITICALCVSS 9.8≥ 4.22, ≤ 4.22.9m≥ 4.23, ≤ 4.23.9+3 more2022-02-04
CVE-2021-28503 [CRITICAL] CWE-305 CVE-2021-28503: The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials w
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
nvd
CVE-2015-3214P3MEDIUMCVSS 6.9PoCv4.12v4.13+2 more2015-08-31
CVE-2015-3214 [MEDIUM] CWE-119 CVE-2015-3214: The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not dist
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
nvd
CVE-2015-8236P3CRITICALCVSS 10.0≤ 4.11.11v4.12.5.2+53 more2015-11-19
CVE-2015-8236 [CRITICAL] CWE-264 CVE-2015-8236: Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.
nvd
CVE-2015-5165P3CRITICALCVSS 9.3v4.12v4.13+2 more2015-08-12
CVE-2015-5165 [CRITICAL] CWE-908 CVE-2015-5165: The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
nvd
CVE-2015-3209P3HIGHCVSS 7.5v4.12v4.13+2 more2015-06-15
CVE-2015-3209 [HIGH] CWE-787 CVE-2015-3209: Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitr
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
nvd
CVE-2021-28506P3CRITICALCVSS 9.1≥ 4.24.0, ≤ 4.24.7m≥ 4.25.0, ≤ 4.25.3+3 more2022-01-14
CVE-2021-28506 [CRITICAL] CWE-285 CVE-2021-28506: An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authori
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
nvd
CVE-2019-17596P3HIGHCVSS 7.5≤ 4.23.1f2019-10-24
CVE-2019-17596 [HIGH] CWE-436 CVE-2019-17596: Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic conta
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.
nvd
CVE-2021-28505P3HIGHCVSS 7.5≥ 4.26, < 4.26.4m≥ 4.27, < 4.27.1f2022-04-14
CVE-2021-28505 [HIGH] CWE-284 CVE-2021-28505: On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applie
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
nvd
CVE-2023-24509P3HIGHCVSS 7.8≥ 4.23, ≤ 4.23.13m≥ 4.24.0, < 4.24.11m+4 more2023-04-13
CVE-2023-24509 [HIGH] CWE-269 CVE-2023-24509: On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.
nvd
CVE-2023-24511P3HIGHCVSS 7.5≥ 4.26.0, < 4.26.10m≥ 4.27.0, < 4.27.9m+2 more2023-04-12
CVE-2023-24511 [HIGH] CWE-401 CVE-2023-24511: On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulner
nvd
CVE-2021-28504P3HIGHCVSS 7.5≥ 4.26, < 4.26.4m≥ 4.27, < 4.27.1f2022-04-01
CVE-2021-28504 [HIGH] CWE-284 CVE-2021-28504: On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-lis
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.
nvd
CVE-2020-15897P3HIGHCVSS 7.5fixed in 4.21.12m≥ 4.22, < 4.22.7m+2 more2020-10-26
CVE-2020-15897 [HIGH] CVE-2020-15897: Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
nvd
CVE-2023-24512P3MEDIUMCVSS 6.5≥ 4.26.0, < 4.26.10m≥ 4.27.0, < 4.27.9m+2 more2023-04-25
CVE-2023-24512 [MEDIUM] CWE-284 CVE-2023-24512: On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI re
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note:
nvd
CVE-2021-28500P3HIGHCVSS 7.8fixed in 4.20≥ 4.21.0, ≤ 4.21.14m+5 more2022-01-14
CVE-2021-28500 [HIGH] CWE-285 CVE-2021-28500: An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by th
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
nvd
1 / 3Next →