CVE-2025-1259
- EPSS 0.05%
- Published 04.03.2025 20:15:37
- Last modified 04.03.2025 20:15:37
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
CVE-2024-7095
- EPSS 0.06%
- Published 10.01.2025 21:15:13
- Last modified 14.01.2025 15:15:27
On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process bein...
CVE-2024-5872
- EPSS 0.06%
- Published 10.01.2025 21:15:13
- Last modified 10.01.2025 21:15:13
On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
CVE-2024-6387
- EPSS 38.58%
- Published 01.07.2024 13:15:06
- Last modified 30.09.2025 13:52:23
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...
CVE-2023-3646
- EPSS 0.15%
- Published 29.08.2023 17:15:12
- Last modified 21.11.2024 08:17:44
On affected platforms running Arista EOS with mirroring to multiple destinations configured, an internal system error may trigger a kernel panic and cause system reload.
CVE-2023-24548
- EPSS 0.05%
- Published 29.08.2023 17:15:11
- Last modified 21.11.2024 07:48:06
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets. The device will continue to be susceptible t...
CVE-2023-24510
- EPSS 0.19%
- Published 05.06.2023 22:15:11
- Last modified 21.11.2024 07:48:01
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
CVE-2023-24512
- EPSS 0.09%
- Published 25.04.2023 21:15:10
- Last modified 21.11.2024 07:48:01
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Age...
CVE-2023-24509
- EPSS 0.05%
- Published 13.04.2023 20:15:08
- Last modified 21.11.2024 07:48:00
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading ...
CVE-2023-24511
- EPSS 0.03%
- Published 12.04.2023 21:15:16
- Last modified 21.11.2024 07:48:01
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automat...