Arista Eos vulnerabilities
44 known vulnerabilities affecting arista/eos.
Total CVEs
44
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH17MEDIUM14LOW4
Vulnerabilities
Page 1 of 3
CVE-2024-6387HIGHCVSS 8.1PoC≥ 4.32.0, ≤ 4.32.1f2024-07-01
CVE-2024-6387 [HIGH] CWE-364 CVE-2024-6387: A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race con
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
nvd
CVE-2023-3646HIGHCVSS 7.5≥ 4.28.2f, ≤ 4.28.5.1m≥ 4.29.0, < 4.29.2f2023-08-29
CVE-2023-3646 [MEDIUM] CWE-125 CVE-2023-3646: On affected platforms running Arista EOS with mirroring to multiple destinations configured, an inte
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.
nvd
CVE-2023-24548MEDIUMCVSS 6.5≥ 4.22.1f, ≤ 4.22.13m≥ 4.23.0, ≤ 4.23.14m+2 more2023-08-29
CVE-2023-24548 [MEDIUM] CWE-120 CVE-2023-24548: On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets recei
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.
nvd
CVE-2023-24510HIGHCVSS 7.5≤ 4.25.10m≥ 4.26.0, < 4.26.10m+3 more2023-06-05
CVE-2023-24510 [HIGH] CWE-755 CVE-2023-24510: On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to r
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
nvd
CVE-2023-24512MEDIUMCVSS 6.5≥ 4.26.0, < 4.26.10m≥ 4.27.0, < 4.27.9m+2 more2023-04-25
CVE-2023-24512 [HIGH] CWE-284 CVE-2023-24512: On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI re
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: T
nvd
CVE-2023-24509HIGHCVSS 7.8≥ 4.23, ≤ 4.23.13m≥ 4.24.0, < 4.24.11m+4 more2023-04-13
CVE-2023-24509 [CRITICAL] CWE-269 CVE-2023-24509: On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerabili
nvd
CVE-2023-24511HIGHCVSS 7.5≥ 4.26.0, < 4.26.10m≥ 4.27.0, < 4.27.9m+2 more2023-04-12
CVE-2023-24511 [MEDIUM] CWE-401 CVE-2023-24511: On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vuln
nvd
CVE-2021-28510HIGHCVSS 7.5fixed in 4.23.10≥ 4.24.0, < 4.24.8+3 more2023-01-26
CVE-2021-28510 [MEDIUM] CWE-400 CVE-2021-28510: For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling me
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
nvd
CVE-2021-28511MEDIUMCVSS 6.5≤ 4.24.9≥ 4.25.0, ≤ 4.25.8+2 more2022-08-05
CVE-2021-28511 [MEDIUM] CWE-284 CVE-2021-28511: This advisory documents the impact of an internally found vulnerability in Arista EOS for security A
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed
nvd
CVE-2021-28508MEDIUMCVSS 6.1≥ 4.23, ≤ 4.23.11≥ 4.24, < 4.24.10+3 more2022-05-26
CVE-2021-28508 [MEDIUM] CWE-255 CVE-2021-28508: This advisory documents the impact of an internally found vulnerability in Arista EOS state streamin
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized users, which could cause IPsec traffi
nvd
CVE-2021-28509MEDIUMCVSS 6.1≥ 4.23, ≤ 4.23.11≥ 4.24, < 4.24.10+3 more2022-05-26
CVE-2021-28509 [MEDIUM] CWE-255 CVE-2021-28509: This advisory documents the impact of an internally found vulnerability in Arista EOS state streamin
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized users, which could cause MACsec traf
nvd
CVE-2021-28505HIGHCVSS 7.5≥ 4.26, < 4.26.4m≥ 4.27, < 4.27.1f2022-04-14
CVE-2021-28505 [HIGH] CWE-284 CVE-2021-28505: On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applie
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
nvd
CVE-2021-28504HIGHCVSS 7.5≥ 4.26, < 4.26.4m≥ 4.27, < 4.27.1f2022-04-01
CVE-2021-28504 [HIGH] CWE-284 CVE-2021-28504: On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-lis
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.
nvd
CVE-2021-28503CRITICALCVSS 9.8≥ 4.22, ≤ 4.22.9m≥ 4.23, ≤ 4.23.9+3 more2022-02-04
CVE-2021-28503 [HIGH] CWE-305 CVE-2021-28503: The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials w
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
nvd
CVE-2021-28506CRITICALCVSS 9.1≥ 4.24.0, ≤ 4.24.7m≥ 4.25.0, ≤ 4.25.3+3 more2022-01-14
CVE-2021-28506 [CRITICAL] CWE-285 CVE-2021-28506: An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authori
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
nvd
CVE-2021-28507HIGHCVSS 7.1≥ 4.23.0, ≤ 4.23.9m≥ 4.24.0, ≤ 4.24.7m+9 more2022-01-14
CVE-2021-28507 [MEDIUM] CWE-284 CVE-2021-28507: An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.
nvd
CVE-2021-28500HIGHCVSS 7.8fixed in 4.20≥ 4.21.0, ≤ 4.21.14m+5 more2022-01-14
CVE-2021-28500 [CRITICAL] CWE-285 CVE-2021-28500: An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by th
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
nvd
CVE-2021-28496MEDIUMCVSS 6.5≥ 4.22, ≤ 4.22.7m≥ 4.23, < 4.23.10+3 more2021-10-21
CVE-2021-28496 [MEDIUM] CWE-311 CVE-2021-28496: On systems running Arista EOS and CloudEOS with the affected release version, when using shared secr
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.
nvd
CVE-2020-25686LOWCVSS 3.7≥ 4.21, < 4.21.14m≥ 4.22, < 4.22.9m+3 more2021-01-20
CVE-2020-25686 [LOW] CVE-2020-25686: A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to
nvd
CVE-2020-25685LOWCVSS 3.7≥ 4.21, < 4.21.14m≥ 4.22, < 4.22.9m+3 more2021-01-20
CVE-2020-25685 [LOW] CVE-2020-25685: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to
nvd
1 / 3Next →