Where
-Infinity
0

Arista Arista Edge Threat Management (NGFW)Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting

Risk 44
Severity
5.8
First published (updated )

Arista Arista Edge Threat Management (NGFW)Arista Edge Threat Management NGFW UI Arbitrary Command Execution

Risk 52
Severity
7
First published (updated )

Arista Arista Edge Threat Management (Arista Next Generation Firewall)Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection

Risk 52
Severity
7
First published (updated )

Arista Arista Edge Threat Management (NGFW)Arista Edge Threat Management NGFW Reports Application Insecure Input Validation

Risk 52
Severity
7
First published (updated )

Arista Arista Edge Threat Management NGFWArista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection

Risk 52
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arista Arista EOSArista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled

Risk 43
Severity
8.2
First published (updated )

Arista Networks Arista EOSArista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Risk 65
Severity
6.9
First published (updated )

Arista CloudVision Exchange (CVX)Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session

Risk 71
Severity
8.7
First published (updated )

Arista CloudVision eXchangeArista CloudVision Exchange Cluster Instability via Unexpected Switch Messages

Risk 40
Severity
7.1
First published (updated )

Arista EOS SysDB AgentArista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arista Arista EOSArista EOS Dataplane Denial of Service via Malformed IPsec Packet

Risk 47
Severity
8.7
First published (updated )

Arista EOSOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).

Risk 68
Severity
7.2
First published (updated )

Arista Arista EOSOn affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).

Risk 68
Severity
7.2
First published (updated )

Arista EOSIn Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.

Risk 38
Severity
6.5
First published (updated )

SUSE Linux Enterprise ServerLinux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Risk 91
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arista EOSOn affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o

Risk 26
Severity
5.3
First published (updated )

Arista EOSA specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted

Risk 29
Severity
7.1
EPSS
0.02%
First published (updated )

Arista NG FirewallArista NG Firewall load_capture_settings Exposed Dangerous Function Information Disclosure Vulnerability

Risk 53
First published (updated )
Advisory
ZDI-25-1018

Arista NG FirewallArista NG Firewall runTroubleshooting Command Injection Remote Code Execution Vulnerability

Risk 72
First published (updated )
Advisory
ZDI-25-1020

Arista NG FirewallZDI-25-1020: Arista NG Firewall runTroubleshooting Command Injection Remote Code Execution Vulnerability

Risk 72
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arista NG FirewallZDI-25-1019: Arista NG Firewall replace_marker Exposed Dangerous Function Authentication Bypass Vulnerability

Risk 45
First published (updated )

Arista NG FirewallZDI-25-1018: Arista NG Firewall load_capture_settings Exposed Dangerous Function Information Disclosure Vulnerability

Risk 53
First published (updated )

Arista EOSOn affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.

Risk 23
Severity
5.6
EPSS
0.03%
First published (updated )

Arubanetworks ArubaosAuthenticated Command Injection Vulnerability in AOS-8 Controller/Mobility Conductor Web-Based Management Interface via the CLI Binaryalong with accounting controls for tracking and logging user activities and resource usage.

Risk 66
Severity
7.2
First published (updated )

Arista EOSOn affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do n

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arista EOSOn affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c

Risk 20
Severity
3.8
First published (updated )

Arista EOSn affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets.

Risk 15
Severity
2.6
First published (updated )

Arista EOSOn affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal

Risk 27
Severity
5.3
First published (updated )

Arista EOSOn affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries.

Risk 40
Severity
6.5
First published (updated )

Arista EOSOn affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropp

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203