Arista Networks Eos vulnerabilities
76 known vulnerabilities affecting arista_networks/eos.
Total CVEs
76
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH22MEDIUM39LOW7
Vulnerabilities
Page 4 of 4
CVE-2026-73443P4MEDIUMCVSS 4.7≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+2 more2026-09-16
CVE-2026-73443 [MEDIUM] CWE-294 CVE-2026-73443: On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthentic
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prev
nvd
CVE-2023-24548P4MEDIUMCVSS 6.5≥ 4.25.0F, ≤ =4.25.0F≥ 4.24.0, ≤ <=4.24.11M+2 more2023-08-29
CVE-2023-24548 [MEDIUM] CWE-120 CVE-2023-24548: On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets recei
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible to the issue until remediation is in place.
nvd
CVE-2024-9135P4MEDIUMCVSS 5.3v4.33.0≥ 4.31.0, ≤ 4.31.5+4 more2025-03-04
CVE-2024-9135 [MEDIUM] CWE-401 CVE-2024-9135: On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.
nvd
CVE-2026-73451P4MEDIUMCVSS 4.8≥ 4.36.0, ≤ 4.36.0.1F≥ 4.35.0, ≤ 4.35.4M+4 more2026-09-15
CVE-2026-73451 [MEDIUM] CWE-1419 CVE-2026-73451: On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs confi
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet p
nvd
CVE-2024-7095P4MEDIUMCVSS 4.3≥ 4.32.0F, ≤ 4.32.2F≥ 4.31.0M, ≤ 4.31.4M+9 more2025-01-10
CVE-2024-7095 [MEDIUM] CWE-401 CVE-2024-7095: On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is restarted) and memory pressure for other
nvd
CVE-2026-73440P4MEDIUMCVSS 4.2≥ 4.36.0F, ≤ 4.36.1F≥ 4.35.0F, ≤ 4.35.5M+3 more2026-09-16
CVE-2026-73440 [MEDIUM] CWE-212 CVE-2026-73440: On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured,
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who gains access to this sensitive information could leverage it to perform
nvd
CVE-2026-19640P4MEDIUMCVSS 4.2≥ 4.36.0F, ≤ 4.36.0.1F≥ 4.35.0F, ≤ 4.35.5M+3 more2026-09-16
CVE-2026-19640 [MEDIUM] CWE-863 CVE-2026-19640: On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Networ
On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this is
nvd
CVE-2025-7048P4MEDIUMCVSS 4.3≥ 4.34.3.0, ≤ 4.34.3.1M≥ 4.33.0, ≤ 4.33.5M+3 more2026-01-06
CVE-2025-7048 [MEDIUM] CWE-805 CVE-2025-7048: On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can c
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.
nvd
CVE-2025-8870P4MEDIUMCVSS 4.9v4.34.2FX2025-11-14
CVE-2025-8870 [MEDIUM] CWE-248 CVE-2025-8870: On affected platforms running Arista EOS, certain serial console input might result in an unexpected
On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153
nvd
CVE-2026-73442P4LOWCVSS 3.0≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+2 more2026-09-16
CVE-2026-73442 [LOW] CWE-532 CVE-2026-73442: On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication cred
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access
nvd
CVE-2025-3456P4LOWCVSS 3.8v4.34.0F≥ 4.33.0, ≤ 4.33.3F+4 more2025-08-25
CVE-2025-3456 [LOW] CWE-532 CVE-2025-3456: On affected platforms running Arista EOS, the global common encryption key configuration may be logg
On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords in cases where symmetric passwords ar
nvd
CVE-2026-77191P4LOWCVSS 2.6≥ 4.35.0, ≤ 4.35.0.3F≥ 4.34.0, ≤ 4.34.5M+1 more2026-09-14
CVE-2026-77191 [LOW] CWE-862 CVE-2026-77191: An authenticated supplicant on an adjacent network may bypass intended network authorization policy
An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.
nvd
CVE-2026-75944P4LOWCVSS 2.6≥ 4.36.0, ≤ 4.36.1F2026-09-14
CVE-2026-75944 [LOW] CWE-459 CVE-2026-75944: A race condition during supplicant re-authentication may leave a stale ACL entry that persists in th
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to
nvd
CVE-2026-75945P4LOWCVSS 2.6≥ 4.36.0, ≤ 4.36.1F2026-09-14
CVE-2026-75945 [LOW] CWE-459 CVE-2026-75945: A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host al
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
nvd
CVE-2025-2826P4LOWCVSS 2.6v4.33.2F2025-05-27
CVE-2025-2826 [LOW] CWE-1284 CVE-2025-2826: n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ing
n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The two symptoms of this issue
nvd
CVE-2026-75943P4LOWCVSS 2.6≥ 4.36.0, ≤ 4.36.1F≥ 4.35.0, ≤ 4.35.5M+2 more2026-09-14
CVE-2026-75943 [LOW] CWE-459 CVE-2026-75943: A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
nvd
← Previous4 / 4