Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-5089— Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages

Quick assessment

Affected
Arista Networks EOS / CloudVision eXchange (CVX)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Arista CloudVision eXchange是美国Arista公司的一个面向数据中心和企业网络的控制平面交换平台。 Arista CloudVision eXchange存在安全漏洞,该漏洞源于EOS交换机对来自CVX服务器的特定畸形消息缺乏弹性,CVX服务器对来自EOS交换机的特定畸形消息也缺乏弹性,可能导致Sysdb代理崩溃或CVX代理崩溃,造成拒绝服务。

CVSS 6.5 · Medium EPSS 0.24% · P13

Affected Version Matrix 5

VendorProduct Version RangeStatus
Arista Networks EOS / CloudVision eXchange (CVX) 4.34.0F≤ 4.34.1F affected
4.33.0M≤ 4.33.4M affected
4.32.0M≤ 4.32.6M affected
4.31.0M≤ 4.31.8M affected
4.30.0< 4.31.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-5089

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages
Source: CVE Program / CVE List V5
Vulnerability Description
In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Arista CloudVision eXchange 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Arista CloudVision eXchange是美国Arista公司的一个面向数据中心和企业网络的控制平面交换平台。 Arista CloudVision eXchange存在安全漏洞,该漏洞源于EOS交换机对来自CVX服务器的特定畸形消息缺乏弹性,CVX服务器对来自EOS交换机的特定畸形消息也缺乏弹性,可能导致Sysdb代理崩溃或CVX代理崩溃,造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Arista Networks EOS / CloudVision eXchange (CVX) 4.34.0F ~ 4.34.1F -

II. Public POCs for CVE-2025-5089

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-5089

请登录查看更多情报信息。

Vendor Advisories for CVE-2025-5089 (1)

Same Patch Batch · Arista Networks · 2026-06-05 · 10 CVEs total

CVE-2025-5088 8.3 HIGH Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session
CVE-2025-5090 6.5 MEDIUM Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages
CVE-2026-25621 6.0 MEDIUM Arista Edge Threat Management NGFW Reports Application Insecure Input Validation
CVE-2026-25622 6.0 MEDIUM Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
CVE-2026-25620 6.0 MEDIUM Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
CVE-2026-25623 6.0 MEDIUM Arista Edge Threat Management NGFW UI Arbitrary Command Execution
CVE-2026-2379 5.9 MEDIUM Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is D
CVE-2026-7473 5.8 MEDIUM Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
CVE-2026-25624 5.7 MEDIUM Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting

IV. Related Vulnerabilities

V. Comments for CVE-2025-5089

No comments yet


Leave a comment