Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

EOS — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in EOS, with AI-generated Chinese analysis, references, and POCs.

This page serves as the vulnerability aggregation hub for EOS, a Linux distribution developed by Blue Systems Software, specifically covering Common Weakness Enumeration (CWE) classifications. It collects reported security flaws, ranging from critical privilege escalation risks to minor information disclosures, spanning advisory releases from early 2010 through 2024. By centralizing these records, the platform enables users to track Blue Systems Software advisories as they unfold, providing a clear timeline of when specific patches were issued and deployed. This structured approach allows security professionals to deeply understand the prevalence and impact of a specific weakness class within the EOS ecosystem, observing how similar vulnerabilities manifest across different versions and architectures over time. Furthermore, it supports efficient investigation of a product’s vulnerability history, helping administrators assess their system’s exposure by comparing installed package versions against known affected ranges. The data is sourced directly from official distribution announcements and third-party security trackers, ensuring accuracy and comprehensive coverage of both critical and low-severity issues. This resource is designed for developers, system administrators, and security researchers who require a consolidated view of EOS-specific security trends without navigating fragmented sources. By presenting this information in a unified interface, the page simplifies the process of risk assessment and compliance verification for organizations relying on the EOS operating system in their infrastructure.

Vendor: Arista Networks

CVE ID Title CVSS Severity Published
CVE-2026-2379 Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled CWE-672 5.9 Medium 2026-06-05
CVE-2026-7473 Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass CWE-1023 5.8 Medium 2026-06-05
CVE-2025-8873 Arista EOS Dataplane Denial of Service via Malformed IPsec Packet CWE-1286 7.5 High 2026-06-04
CVE-2023-5502 On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication. CWE-287 5.9 Medium 2026-06-04
CVE-2024-27892 On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled). CWE-306 9.6 Critical 2026-06-04
CVE-2024-27890 On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled). CWE-306 9.6 Critical 2026-06-04
CVE-2024-27891 On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. CWE-284 5.3 Medium 2026-06-04
CVE-2024-6858 In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN. CWE-1287 - - 2026-06-04
CVE-2025-7048 On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o CWE-805 4.3 Medium 2026-01-06
CVE-2025-8872 A specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted CWE-400 6.5 Medium 2025-12-16
CVE-2025-8870 On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device. CWE-248 4.9 Medium 2025-11-14
CVE-2025-6188 On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do n 7.5 High 2025-08-25
CVE-2025-3456 On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c CWE-532 3.8 Low 2025-08-25
CVE-2025-2826 n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. CWE-1284 2.6 Low 2025-05-27
CVE-2025-2796 On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal 5.3 Medium 2025-05-27
CVE-2024-11185 On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. 6.5 Medium 2025-05-27
CVE-2024-9448 On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropp CWE-1284 7.5 High 2025-05-08
CVE-2025-0936 On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly CWE-256 6.5 Medium 2025-05-07
CVE-2024-8000 On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restar CWE-1284 5.3 Medium 2025-03-04
CVE-2024-9135 On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping. CWE-401 5.3 Medium 2025-03-04
CVE-2025-1260 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. CWE-284 9.1 Critical 2025-03-04
CVE-2025-1259 On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. CWE-284 7.7 High 2025-03-04
CVE-2024-5872 On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc. 6.5 Medium 2025-01-10
CVE-2024-7095 On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being term 4.3 Medium 2025-01-10
CVE-2023-3646 On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload. CWE-125 5.9 Medium 2023-08-29
CVE-2023-24548 On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets CWE-120 5.3 Medium 2023-08-29
CVE-2023-24511 On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. CWE-401 5.3 Medium 2023-04-12
CVE-2023-24513 On affected platforms running Arista CloudEOS a size check bypass issue in the Software Forwarding Engine (Sfe) may allow buffer over reads in later code. Additionally, depending on configured options this may cause a recomputation of the TCP checksum ... CWE-126 6.5 Medium 2023-04-12
CVE-2023-24545 On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. CWE-400 7.5 High 2023-04-12
CVE-2023-0452 Econolite EOS traffic control software 加密问题漏洞 CWE-328 9.8 Critical 2023-01-26

All 37 known CVE vulnerabilities affecting EOS with full Chinese analysis, references, and POCs where available.