Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Arista Networks — Vulnerabilities & Security Advisories 129

Browse all 129 CVE security advisories affecting Arista Networks. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Arista Networks specializes in high-performance data center switching and cloud networking solutions, primarily serving enterprise and service provider infrastructure. With sixty-four recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has predominantly featured remote code execution, cross-site scripting, and privilege escalation flaws within its management interfaces and network operating systems. These vulnerabilities often stem from input validation errors or improper access controls in legacy software versions, allowing attackers to gain unauthorized administrative access or disrupt network services. While Arista maintains a robust security posture through regular firmware updates and secure boot mechanisms, past incidents highlight the risks associated with complex network management platforms. The company actively addresses these issues via security advisories, emphasizing the importance of timely patching for deployed infrastructure to mitigate potential exploitation by malicious actors targeting critical network backbone components.

CVE ID Title CVSS Severity Published
CVE-2026-73459 Security Advisory 0160 — EOS CWE-354 7.4 High 2026-09-15
CVE-2026-73446 Security Advisory 0160 — EOS CWE-696 7.4 High 2026-09-15
CVE-2026-73444 On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the — EOS CWE-303 4.7 Medium 2026-09-15
CVE-2026-73437 On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinat — EOS CWE-345 9.6 Critical 2026-09-15
CVE-2026-19655 On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthent — EOS CWE-20 6.5 Medium 2026-09-15
CVE-2026-73458 On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou — EOS CWE-303 8.2 High 2026-09-15
CVE-2026-73467 On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers — EOS CWE-532 6.3 Medium 2026-09-15
CVE-2026-73466 On affected platforms running Arista EOS, under certain circumstances plaintext user passwords — EOS CWE-532 6.3 Medium 2026-09-15
CVE-2026-73465 On affected platforms running Arista EOS, under certain circumstances plaintext private keys — EOS CWE-532 6.3 Medium 2026-09-15
CVE-2026-19641 On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit — EOS CWE-116 5.3 Medium 2026-09-15
CVE-2026-73451 On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can — EOS CWE-1419 4.8 Medium 2026-09-15
CVE-2026-75945 A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. — EOS CWE-459 2.6 Low 2026-09-14
CVE-2026-75944 A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User — EOS CWE-459 2.6 Low 2026-09-14
CVE-2026-75943 A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcem — EOS CWE-459 2.6 Low 2026-09-14
CVE-2026-77191 All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on an — EOS CWE-862 2.6 Low 2026-09-14
CVE-2026-73449 On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADI — EOS CWE-290 5.9 Medium 2026-09-14
CVE-2026-17191 VeloCloud Orchestrator Flow Metrics API SQL Injection — VeloCloud Orchestrator On-Prem CWE-89 9.1 Critical 2026-07-27
CVE-2026-17192 VeloCloud Orchestrator Missing Input Validation SSRF — VeloCloud Orchestrator On-Prem CWE-918 8.5 High 2026-07-27
CVE-2026-16812 VeloCloud Orchestrator OS Command Injection — VeloCloud Orchestrator On-Prem CWE-78 10.0 Critical 2026-07-27
CVE-2026-25624 Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting — Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CWE-79 5.7 Medium 2026-06-05
CVE-2026-25623 Arista Edge Threat Management NGFW UI Arbitrary Command Execution — Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CWE-78 6.0 Medium 2026-06-05
CVE-2026-25622 Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection — Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CWE-78 6.0 Medium 2026-06-05
CVE-2026-25621 Arista Edge Threat Management NGFW Reports Application Insecure Input Validation — Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CWE-78 6.0 Medium 2026-06-05
CVE-2026-25620 Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection — Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) CWE-78 6.0 Medium 2026-06-05
CVE-2026-2379 Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled — EOS CWE-672 5.9 Medium 2026-06-05
CVE-2026-7473 Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass — EOS CWE-1023 5.8 Medium 2026-06-05
CVE-2025-5088 Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session — EOS / CloudVision eXchange (CVX) CWE-269 8.3 High 2026-06-05
CVE-2025-5090 Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages — EOS / CloudVision eXchange (CVX) CWE-20 6.5 Medium 2026-06-05
CVE-2025-5089 Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages — EOS / CloudVision eXchange (CVX) CWE-20 6.5 Medium 2026-06-05
CVE-2025-8873 Arista EOS Dataplane Denial of Service via Malformed IPsec Packet — EOS CWE-1286 7.5 High 2026-06-04

This page lists every published CVE security advisory associated with Arista Networks. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.