Arista Networks Eos vulnerabilities
76 known vulnerabilities affecting arista_networks/eos.
Total CVEs
76
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH22MEDIUM39LOW7
Vulnerabilities
Page 1 of 4
CVE-2026-7473P1MEDIUMCVSS 5.8KEVv4.36.0≥ 4.35.0, ≤ 4.35+5 more2026-06-05
CVE-2026-7473 [MEDIUM] CWE-1023 CVE-2026-7473: On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (V
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation
nvd
CVE-2026-73456P2CRITICALCVSS 10.0≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+1 more2026-09-16
CVE-2026-73456 [CRITICAL] CWE-94 CVE-2026-73456: Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampli
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
nvd
CVE-2026-73453P2CRITICALCVSS 10.0≥ 4.36.0F, ≤ 4.36.1F≥ 4.35.0F, ≤ 4.35.5M+6 more2026-09-16
CVE-2026-73453 [CRITICAL] CWE-94 CVE-2026-73453: An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session
nvd
CVE-2026-73464P2HIGHCVSS 8.8≥ 4.29.0F, < 4.30.0F≥ 4.30.0F, < 4.31.0F+6 more2026-09-16
CVE-2026-73464 [HIGH] CWE-94 CVE-2026-73464: On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a sp
On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.
nvd
CVE-2026-73447P2CRITICALCVSS 9.1≥ 4.30.2F, < 4.31.0F≥ 4.31.0F, < 4.32.0F+5 more2026-09-16
CVE-2026-73447 [CRITICAL] CWE-78 CVE-2026-73447: A privileged attacker can exploit certain operation to execute arbitrary commands with root privileg
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. Th
nvd
CVE-2024-27890P2CRITICALCVSS 9.6≥ 4.29.0, ≤ 4.29.7M≥ 4.28.0, ≤ 4.28.10M+4 more2026-06-04
CVE-2024-27890 [CRITICAL] CWE-306 CVE-2024-27890: Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
nvd
CVE-2026-73437P3CRITICALCVSS 9.6≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+2 more2026-09-15
CVE-2026-73437 [CRITICAL] CWE-345 CVE-2026-73437: On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay confi
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent would forward it to clients without validating the source. This could al
nvd
CVE-2026-73454P3HIGHCVSS 8.1≥ 4.30.0F, < 4.31.0F≥ 4.31.0F, < 4.32.0F+5 more2026-09-16
CVE-2026-73454 [HIGH] CWE-77 CVE-2026-73454: On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz con
On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.
nvd
CVE-2024-27892P3CRITICALCVSS 9.6≥ 4.31.0, ≤ 4.31.2F≥ 4.30.0, ≤ 4.30.5M+6 more2026-06-04
CVE-2024-27892 [CRITICAL] CWE-306 CVE-2024-27892: Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being applied to the switch.
nvd
CVE-2021-28506P3CRITICALCVSS 9.1≥ 4.26.2F, ≤ 4.26.0≥ 4.25.5.1M, ≤ 4.25.5+3 more2022-01-14
CVE-2021-28506 [CRITICAL] CWE-285 CVE-2021-28506: An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authori
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
nvd
CVE-2026-73439P3HIGHCVSS 7.5≥ 4.33.2F, ≤ 4.33.8M≥ 4.34.0F, ≤ 4.34.6M+2 more2026-09-16
CVE-2026-73439 [HIGH] CWE-842 CVE-2026-73439: On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on t
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to correctly enforce the rules in this policy if both a group rule and a user rule for the same path is present in the policy. Under certain
nvd
CVE-2025-1260P3CRITICALCVSS 9.1≥ 4.33.0, ≤ 4.33.1≥ 4.32.0, ≤ 4.32.3+4 more2025-03-04
CVE-2025-1260 [CRITICAL] CWE-284 CVE-2025-1260: On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
nvd
CVE-2026-73461P3HIGHCVSS 8.0≥ 4.29.0F, < 4.30.0F≥ 4.30.0F, < 4.31.0F+6 more2026-09-16
CVE-2026-73461 [HIGH] CWE-266 CVE-2026-73461: On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.
nvd
CVE-2026-73458P3HIGHCVSS 8.2≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+2 more2026-09-15
CVE-2026-73458 [HIGH] CWE-303 CVE-2026-73458: On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD)
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).
nvd
CVE-2026-73435P3HIGHCVSS 8.2≥ 4.36.0F, ≤ 4.36.1F≥ 4.35.0F, ≤ 4.35.5M+3 more2026-09-16
CVE-2026-73435 [HIGH] CWE-345 CVE-2026-73435: On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
nvd
CVE-2024-9448P3HIGHCVSS 7.5≥ 4.33.0, ≤ 4.33.0F≥ 4.32.0, ≤ 4.32.3M+2 more2025-05-08
CVE-2024-9448 [HIGH] CWE-1284 CVE-2024-9448: On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cau
On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being
nvd
CVE-2026-73455P3HIGHCVSS 7.5≥ 1.0.0, < 4.33.0F≥ 4.33.0F, ≤ 4.33.8M+3 more2026-09-16
CVE-2026-73455 [HIGH] CWE-130 CVE-2026-73455: On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
nvd
CVE-2025-6188P3HIGHCVSS 7.5≥ 4.33.0, ≤ 4.33.1F≥ 4.33.1.0, ≤ 4.33.1.2F+3 more2025-08-25
CVE-2025-6188 [HIGH] CWE-290 CVE-2025-6188: On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may b
On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of authentication.
nvd
CVE-2025-8873P3HIGHCVSS 7.5≥ 4.33.0M, ≤ 4.33.4M≥ 4.32.0M, ≤ 4.32.6.1M+3 more2026-06-04
CVE-2025-8873 [HIGH] CWE-1286 CVE-2025-8873: On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec
nvd
CVE-2021-28505P3HIGHCVSS 7.5≥ 4.26.3M, ≤ 4.26.0≥ 4.27.0F, ≤ 4.27.02022-04-14
CVE-2021-28505 [HIGH] CWE-284 CVE-2021-28505: On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applie
On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol.
nvd
1 / 4Next →