SecAlerts
arista logo

arista

Security Risk Profile

56
/100
medium

Security Risk Score

Comprehensive risk assessment based on 137 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 15, 2014 to present

137
Total CVEs
77
Critical+High
4
Exploited
28
Unpatched

Threat Assessment

Avg CVSS
7.2
Base severity
Avg EPSS
14%
Exploit probability
Unpatched
28
Critical/High
Risk Level
56/100
medium
⚠️ 4 Active Exploits

Severity Distribution

Critical
21
High
56
Medium
48
Low
5

Exploit Likelihood

>50% chance
1
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
Buffer Overflow
6
2
Input Validation
5
3
Command Injection
4
4
SQL Injection
3
5
OS Command Injection
3

Most Affected Products

1. Juniper Junos349
2. Arista EOS256
3. IBM QRadar Security Information and Event Manager172
4. SUSE Linux Enterprise Server60
5. IBM QRadar Vulnerability Manager60

Recent Vulnerabilities

See more →
CVE-2026-31431
CVSS 7.8high

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

4/22/2026⚠ Exploited
CVE-2025-7048
CVSS 5.3medium

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o

1/6/2026
CVE-2025-8872
CVSS 7.1EPSS 0%high

A specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted

12/16/2025
ZDI-25-1018
unknown

Arista NG Firewall load_capture_settings Exposed Dangerous Function Information Disclosure Vulnerability

11/25/2025🔧 No Patch
ZDI-25-1020
unknown

Arista NG Firewall runTroubleshooting Command Injection Remote Code Execution Vulnerability

11/25/2025🔧 No Patch
ZDI-CAN-27310
unknown

ZDI-25-1020: Arista NG Firewall runTroubleshooting Command Injection Remote Code Execution Vulnerability

11/25/2025🔧 No Patch
ZDI-CAN-27007
unknown

ZDI-25-1019: Arista NG Firewall replace_marker Exposed Dangerous Function Authentication Bypass Vulnerability

11/25/2025🔧 No Patch
ZDI-CAN-27006
unknown

ZDI-25-1018: Arista NG Firewall load_capture_settings Exposed Dangerous Function Information Disclosure Vulnerability

11/25/2025🔧 No Patch
CVE-2025-8870
CVSS 5.6EPSS 0%medium

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.

11/14/2025
CVE-2025-37133
CVSS 7.2high

Authenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage.

10/14/2025🔧 No Patch

Monitor arista in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.