Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Arista Networks — Vulnerabilities & Security Advisories 129

Browse all 129 CVE security advisories affecting Arista Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Arista Networks specializes in high-performance data center switching and cloud networking solutions, primarily serving enterprise and service provider infrastructure. With sixty-four recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has predominantly featured remote code execution, cross-site scripting, and privilege escalation flaws within its management interfaces and network operating systems. These vulnerabilities often stem from input validation errors or improper access controls in legacy software versions, allowing attackers to gain unauthorized administrative access or disrupt network services. While Arista maintains a robust security posture through regular firmware updates and secure boot mechanisms, past incidents highlight the risks associated with complex network management platforms. The company actively addresses these issues via security advisories, emphasizing the importance of timely patching for deployed infrastructure to mitigate potential exploitation by malicious actors targeting critical network backbone components.

CVE ID Title CVSS Severity Published
CVE-2026-93952 Security Advisory 0183 — VeloCloud Orchestrator (VCO) On-Prem CWE-20 10.0 Critical 2026-09-22
CVE-2026-73462 On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I — EOS CWE-125 6.5 Medium 2026-09-16
CVE-2026-73457 Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users. — EOS CWE-532 5.3 Medium 2026-09-16
CVE-2026-73456 Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch. — EOS CWE-94 10.0 Critical 2026-09-16
CVE-2026-73442 On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for — EOS CWE-532 3.0 Low 2026-09-16
CVE-2026-73443 On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef — EOS CWE-294 4.7 Medium 2026-09-16
CVE-2026-86107 Security Advisory 0180 — VeloCloud CWE-787 5.9 Medium 2026-09-16
CVE-2026-86106 Security Advisory 0179 — VeloCloud Edge CWE-306 9.6 Critical 2026-09-16
CVE-2026-77190 Security Advisory 0177 — EOS CWE-20 6.5 Medium 2026-09-16
CVE-2026-73468 Security Advisory 0175 — EOS CWE-670 6.5 Medium 2026-09-16
CVE-2026-73440 Security Advisory 0178 — EOS CWE-212 4.2 Medium 2026-09-16
CVE-2026-73469 Security Advisory 0176 — EOS CWE-863 5.8 Medium 2026-09-16
CVE-2026-73453 Security Advisory 0174 — EOS CWE-94 10.0 Critical 2026-09-16
CVE-2026-73455 Security Advisory 0173 — EOS CWE-130 7.5 High 2026-09-16
CVE-2026-73438 Security Advisory 0172 — EOS CWE-617 5.3 Medium 2026-09-16
CVE-2026-73436 Security Advisory 0171 — EOS CWE-1284 6.5 Medium 2026-09-16
CVE-2026-73435 Security Advisory 0171 — EOS CWE-345 8.2 High 2026-09-16
CVE-2026-19640 Security Advisory 0170 — EOS CWE-863 4.2 Medium 2026-09-16
CVE-2026-73463 Security Advisory 0169 — EOS CWE-362 5.3 Medium 2026-09-16
CVE-2026-73445 Security Advisory 0167 — EOS CWE-20 4.9 Medium 2026-09-16
CVE-2026-2380 Security Advisory 0168 — EOS CWE-256 7.4 High 2026-09-16
CVE-2026-73464 Security Advisory 0166 — EOS CWE-94 8.8 High 2026-09-16
CVE-2026-73454 Security Advisory 0165 — EOS CWE-77 8.1 High 2026-09-16
CVE-2026-73439 Security Advisory 0164 — EOS CWE-842 7.5 High 2026-09-16
CVE-2026-73461 Security Advisory 0163 — EOS CWE-266 8.0 High 2026-09-16
CVE-2026-73447 Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request — EOS CWE-78 9.1 Critical 2026-09-16
CVE-2026-86109 Security Advisory 0182 — VeloCloud Edge CWE-347 6.6 Medium 2026-09-16
CVE-2026-86108 Security Advisory 0181 — VeloCloud Edge CWE-78 8.0 High 2026-09-16
CVE-2026-73450 Security Advisory 0161 — EOS CWE-345 6.9 Medium 2026-09-16
CVE-2026-73460 Security Advisory 0160 — EOS CWE-863 6.1 Medium 2026-09-15

This page lists every published CVE security advisory associated with Arista Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.