Vulnerabilidades en Arista Networks

129 resultados
Análisis Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2026-77191LOWAll of the CVEs covered in this advisory apply to affected platforms running Arista EOS with 802.1X authentication and authorization enabled and Access Control Lists (ACLs) configured for per-supplicant policy enforcement. An authenticated supplicant on anEPSS 0.2%CVE-2026-75944MEDIUMA race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. UserEPSS 0.2%CVE-2026-73463MEDIUMSecurity Advisory 0169EPSS 0.2%CVE-2026-73442LOWOn affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forEPSS 0.2%CVE-2025-54548MEDIUMOn affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)EPSS 0.2%CVE-2026-73437MEDIUMOn affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper/destinatEPSS 0.2%CVE-2026-75945LOWA race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.EPSS 0.2%CVE-2026-75943LOWA brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcemEPSS 0.2%CVE-2022-29071MEDIUMThis advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vu ...EPSS 0.2%CVE-2024-8000MEDIUMOn affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restarEPSS 0.2%CVE-2026-73460HIGHSecurity Advisory 0160EPSS 0.2%CVE-2025-2796MEDIUMOn affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normalEPSS 0.2%CVE-2026-19655HIGHOn affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information option, an unauthentEPSS 0.2%CVE-2026-19640LOWSecurity Advisory 0170EPSS 0.2%CVE-2026-73435HIGHSecurity Advisory 0171EPSS 0.2%CVE-2025-7048MEDIUMOn affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption oEPSS 0.2%CVE-2026-73459HIGHSecurity Advisory 0160EPSS 0.2%CVE-2025-8870MEDIUMOn affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.EPSS 0.2%CVE-2024-9133MEDIUMA user with administrator privileges is able to retrieve authentication tokensEPSS 0.2%CVE-2026-73450HIGHSecurity Advisory 0161EPSS 0.2%