PatchSiren

Arista CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Arista CVE published 2026-07-27

CVE-2026-16812

Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability. The vulnerability allows attackers to inject OS commands. This is an executive overview: Arista VeloCloud Orchestrator On-Prem is affected by an OS command injection vulnerability. The vulnerability class is OS command injection, which can lead to potential operational impact, including unauthorized command execution. The source con [truncated]

HIGH Arista CVE published 2017-01-23

CVE-2016-9012

CVE-2016-9012 describes a high-severity authorization flaw in Arista CloudVision Portal (CVP). An authenticated remote user could reach internal configuration mechanisms through the management plane by making a request associated with /web/system/console/bundle. The vulnerability applies to CVP versions before 2016.1.2.1, with NVD listing affected CPE versions through 2016.1.2.0.