CVE-2025-5090: Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages
CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access to the connected switch to be able to send custom TCP packets to the CVX.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5090?
CVE-2025-5090 has a high severity rating of 7.1.
How do I fix CVE-2025-5090?
You can fix CVE-2025-5090 by upgrading to a remediated software version, specifically version 4.34.2F or later in the 4.34.x train, version 4.33.5M or later in the 4.33.x train, or version 4.32.7M or later in the 4.32.x train.
What risks are associated with CVE-2025-5090?
The risks associated with CVE-2025-5090 include potential denial of service (DoS) conditions due to crashes in the Arista CloudVision Exchange cluster.
What causes CVE-2025-5090?
CVE-2025-5090 is caused by Arista CloudVision Exchange's inability to handle unexpected messages from connected switches.
Who is affected by CVE-2025-5090?
Users of the Arista CloudVision eXchange software are affected by CVE-2025-5090.