Vulnerabilidades em Arista Networks

129 resultados
Análise Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2025-6979HIGHCaptive Portal can allow authentication bypassEPSS 0.5%CVE-2024-4578HIGHPrivilege escalation in Arista Wireless Access PointsEPSS 0.5%CVE-2026-73464HIGHSecurity Advisory 0166EPSS 0.5%CVE-2024-9188HIGHSpecially constructed queries cause cross platform scripting leaking administrator tokensEPSS 0.5%CVE-2024-7095MEDIUMOn affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being termEPSS 0.5%CVE-2023-24548MEDIUMOn affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packetsEPSS 0.5%CVE-2026-73455HIGHSecurity Advisory 0173EPSS 0.5%CVE-2021-28509MEDIUMTerminAttr streams MACsec sensitive data in clear text to other authorized users in CVPEPSS 0.5%CVE-2025-6980HIGHCaptive Portal can expose sensitive informationEPSS 0.5%CVE-2021-28496MEDIUMIn Arista's EOS software affected releases, the shared secret profiles sensitive configuration might be leaked when displaying output over eAPI or other JSON outputs to authenticated users on the device.EPSS 0.4%CVE-2025-1260CRITICALOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.EPSS 0.4%CVE-2024-47518MEDIUMSpecially constructed queries targeting ETM could discover active remote access sessionsEPSS 0.4%CVE-2025-6188HIGHOn affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do nEPSS 0.4%CVE-2024-47520HIGHA user with advanced report application access rights can perform actions for which they are not authorizedEPSS 0.4%CVE-2024-47517MEDIUMExpired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM accessEPSS 0.4%CVE-2025-8873HIGHArista EOS Dataplane Denial of Service via Malformed IPsec PacketEPSS 0.4%CVE-2026-73458CRITICALOn affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rouEPSS 0.4%CVE-2026-86106HIGHSecurity Advisory 0179EPSS 0.4%CVE-2024-9135MEDIUMOn affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.EPSS 0.4%CVE-2026-86107HIGHSecurity Advisory 0180EPSS 0.4%