Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Associated Vulnerability
Found 46 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-7048 On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o Arista NetworksEOS Medium 4.3 2026-01-06 19:15:44 Deep Dive
CVE-2025-8872 A specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted Arista NetworksEOS Medium 6.5 2025-12-16 19:32:21 Deep Dive
CVE-2025-8870 On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device. Arista NetworksEOS Medium 4.9 2025-11-14 15:57:05 Deep Dive
CVE-2025-6188 On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do n Arista NetworksEOS High 7.5 2025-08-25 20:14:23 Deep Dive
CVE-2025-3456 On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c Arista NetworksEOS Low 3.8 2025-08-25 20:02:49 Deep Dive
CVE-2025-5995 Canon EOS Webcam Utility Pro for MAC OS contains an insecure permission issue potentially leading to code execution and privilege escalation Canon USA Inc.Canon EOS Webcam Utility Pro--2025-06-26 19:13:48 Deep Dive
CVE-2025-2826 n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. Arista NetworksEOS Low 2.6 2025-05-27 22:22:52 Deep Dive
CVE-2025-2796 On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal Arista NetworksEOS Medium 5.3 2025-05-27 22:16:53 Deep Dive
CVE-2024-11185 On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. Arista NetworksEOS Medium 6.5 2025-05-27 22:11:30 Deep Dive
CVE-2024-9448 On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropp Arista NetworksEOS High 7.5 2025-05-08 19:14:00 Deep Dive
CVE-2025-0936 On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly Arista NetworksEOS Medium 6.5 2025-05-07 22:52:25 Deep Dive
CVE-2024-8000 On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restar Arista NetworksEOS Medium 5.3 2025-03-04 20:20:54 Deep Dive
CVE-2024-9135 On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping. Arista NetworksEOS Medium 5.3 2025-03-04 20:12:02 Deep Dive
CVE-2025-1260 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. Arista NetworksEOS Critical 9.1 2025-03-04 19:49:00 Deep Dive
CVE-2025-1259 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. Arista NetworksEOS High 7.7 2025-03-04 19:44:34 Deep Dive
CVE-2024-5872 On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc. Arista NetworksEOS Medium 6.5 2025-01-10 20:25:54 Deep Dive
CVE-2024-7095 On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being term Arista NetworksEOS Medium 4.3 2025-01-10 20:19:10 Deep Dive
CVE-2024-6437 On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options ma Arista NetworksEOS-Policy Based Routing (PBR) Medium 5.8 2025-01-10 20:06:36 Deep Dive
CVE-2023-3646 On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload. Arista NetworksEOS Medium 5.9 2023-08-29 16:31:58 Deep Dive
CVE-2023-24548 On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets Arista NetworksEOS Medium 5.3 2023-08-29 16:13:10 Deep Dive