Vulnerabilidades en Arista Networks

129 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2024-27891MEDIUMOn affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.EPSS 0.3%CVE-2026-73462HIGHOn affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IEPSS 0.3%CVE-2026-77190MEDIUMSecurity Advisory 0177EPSS 0.3%CVE-2026-73443MEDIUMOn affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefEPSS 0.3%CVE-2025-0936MEDIUMOn affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possiblyEPSS 0.3%CVE-2026-73436MEDIUMSecurity Advisory 0171EPSS 0.3%CVE-2026-73440LOWSecurity Advisory 0178EPSS 0.3%CVE-2026-25624MEDIUMArista Edge Threat Management NGFW UI Administrative Cross-Site ScriptingEPSS 0.3%CVE-2026-73446HIGHSecurity Advisory 0160EPSS 0.3%CVE-2024-11185MEDIUMOn affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.EPSS 0.3%CVE-2026-2380MEDIUMSecurity Advisory 0168EPSS 0.2%CVE-2026-73438HIGHSecurity Advisory 0172EPSS 0.2%CVE-2026-86109HIGHSecurity Advisory 0182EPSS 0.2%CVE-2026-73449MEDIUMOn affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIEPSS 0.2%CVE-2023-24509CRITICALOn affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading t ...EPSS 0.2%CVE-2025-5089HIGHArista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server MessagesEPSS 0.2%CVE-2025-5090HIGHArista CloudVision Exchange Cluster Instability via Unexpected Switch MessagesEPSS 0.2%CVE-2026-73451MEDIUMOn affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, canEPSS 0.2%CVE-2026-2379HIGHArista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is DisabledEPSS 0.2%CVE-2025-54546HIGHOn affected platforms, restricted users could use SSH port forwarding to access host-internal servicesEPSS 0.2%