Vulnerabilidades en Arista Networks

129 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2026-86106HIGHSecurity Advisory 0179EPSS 0.4%CVE-2026-73439HIGHSecurity Advisory 0164EPSS 0.4%CVE-2024-9135MEDIUMOn affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.EPSS 0.4%CVE-2026-17191HIGHVeloCloud Orchestrator Flow Metrics API SQL InjectionEPSS 0.4%CVE-2026-73445MEDIUMSecurity Advisory 0167EPSS 0.4%CVE-2024-5872MEDIUMOn affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.EPSS 0.3%CVE-2024-47519HIGHBackup uploads to ETM subject to man-in-the-middle interceptionEPSS 0.3%CVE-2025-1259HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.EPSS 0.3%CVE-2026-19641MEDIUMOn affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitEPSS 0.3%CVE-2023-24547MEDIUMOn Arista MOS configuration of a BGP password will cause the password to be logged in clear text.EPSS 0.3%CVE-2023-6068LOWOn affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and someEPSS 0.3%CVE-2025-5088HIGHArista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis SessionEPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2023-5502HIGHOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.EPSS 0.3%CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%CVE-2025-8872HIGHA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restartedEPSS 0.3%CVE-2026-73444MEDIUMOn affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim theEPSS 0.3%CVE-2026-73469MEDIUMSecurity Advisory 0176EPSS 0.3%CVE-2026-17192MEDIUMVeloCloud Orchestrator Missing Input Validation SSRFEPSS 0.3%CVE-2026-73468HIGHSecurity Advisory 0175EPSS 0.3%