Vulnerabilidades em Arista Networks

129 resultados
Análise Vexday

O portfólio de vulnerabilidades da Arista Networks soma 80 CVEs catalogadas, das quais 8 são de severidade crítica e 1 está confirmada em exploração ativa no catálogo KEV da CISA — proporção que coloca o vendor ACIMA da média geral do catálogo em 2,8 vezes, sinalizando atenção redobrada mesmo diante de um volume total relativamente contido. O tipo de falha mais recorrente é CWE-284 (controle de acesso impróprio), padrão que tende a favorecer movimentação lateral e escalada de privilégios em ambientes de rede. A CVE mais perigosa atualmente ativa é CVE-2026-7473, ainda com EPSS de 0,0084, indicando probabilidade de exploração em massa relativamente baixa no curto prazo, mas cuja presença no KEV exige tratamento prioritário. O surgimento de 16 novas CVEs nos últimos 90 dias reforça a necessidade de ciclos de patching contínuos para os operadores desses equipamentos.

CVE-2026-75945LOWA race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.EPSS 0.1%CVE-2025-54545HIGHOn affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.EPSS 0.1%CVE-2025-54547MEDIUMOn affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expiredEPSS 0.1%CVE-2025-3456LOWOn affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-cEPSS 0.1%CVE-2024-7142MEDIUMOn Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on themEPSS 0.1%CVE-2026-73466MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext user passwordsEPSS 0.1%CVE-2026-73465MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext private keysEPSS 0.1%CVE-2026-73467MEDIUMOn affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) serversEPSS 0.1%CVE-2025-54549MEDIUMCryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISOEPSS 0.1%