Vulnerabilidades em Arista Networks

129 resultados
Análise Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2026-73443MEDIUMOn affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefEPSS 0.3%CVE-2025-0936MEDIUMOn affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possiblyEPSS 0.3%CVE-2024-11185MEDIUMOn affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.EPSS 0.3%CVE-2026-73440LOWSecurity Advisory 0178EPSS 0.3%CVE-2026-73468HIGHSecurity Advisory 0175EPSS 0.3%CVE-2026-2380MEDIUMSecurity Advisory 0168EPSS 0.2%CVE-2026-73446HIGHSecurity Advisory 0160EPSS 0.2%CVE-2026-73462HIGHOn affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IEPSS 0.2%CVE-2026-86109HIGHSecurity Advisory 0182EPSS 0.2%CVE-2023-24509CRITICALOn affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading t ...EPSS 0.2%CVE-2025-5089HIGHArista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server MessagesEPSS 0.2%CVE-2025-5090HIGHArista CloudVision Exchange Cluster Instability via Unexpected Switch MessagesEPSS 0.2%CVE-2026-73436MEDIUMSecurity Advisory 0171EPSS 0.2%CVE-2025-54546HIGHOn affected platforms, restricted users could use SSH port forwarding to access host-internal servicesEPSS 0.2%CVE-2026-2379HIGHArista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is DisabledEPSS 0.2%CVE-2026-25621HIGHArista Edge Threat Management NGFW Reports Application Insecure Input ValidationEPSS 0.2%CVE-2026-73438HIGHSecurity Advisory 0172EPSS 0.2%CVE-2026-73442LOWOn affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forEPSS 0.2%CVE-2025-54548MEDIUMOn affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)EPSS 0.2%CVE-2022-29071MEDIUMThis advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vu ...EPSS 0.2%