Vulnerabilidades em Arista Networks

129 resultados
Análise Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2026-86107HIGHSecurity Advisory 0180EPSS 0.4%CVE-2024-5872MEDIUMOn affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.EPSS 0.3%CVE-2024-47519HIGHBackup uploads to ETM subject to man-in-the-middle interceptionEPSS 0.3%CVE-2026-19641MEDIUMOn affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitEPSS 0.3%CVE-2025-1259HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected.EPSS 0.3%CVE-2023-24547MEDIUMOn Arista MOS configuration of a BGP password will cause the password to be logged in clear text.EPSS 0.3%CVE-2023-6068LOWOn affected 7130 Series FPGA platforms running MOS and recent versions of the MultiAccess FPGA, application of ACL’s may result in incorrect operation of the configured ACL for a port resulting in some packets that should be denied being permitted and someEPSS 0.3%CVE-2026-73439HIGHSecurity Advisory 0164EPSS 0.3%CVE-2026-73445MEDIUMSecurity Advisory 0167EPSS 0.3%CVE-2025-5088HIGHArista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis SessionEPSS 0.3%CVE-2023-5502HIGHOn affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.EPSS 0.3%CVE-2026-73457MEDIUMUnder certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.EPSS 0.3%CVE-2024-27892HIGHOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).EPSS 0.3%CVE-2025-8872HIGHA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restartedEPSS 0.3%CVE-2026-73444MEDIUMOn affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim theEPSS 0.3%CVE-2026-73461CRITICALSecurity Advisory 0163EPSS 0.3%CVE-2026-73454HIGHSecurity Advisory 0165EPSS 0.3%CVE-2026-73469MEDIUMSecurity Advisory 0176EPSS 0.3%CVE-2024-27891MEDIUMOn affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.EPSS 0.3%CVE-2026-77190MEDIUMSecurity Advisory 0177EPSS 0.3%