PatchSiren

Arista Networks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Arista Networks CVE published 2026-06-09

CVE-2026-7473

CVE-2026-7473 is a vulnerability in Arista EOS where a tunnel decapsulation configuration is present, allowing an attacker to incorrectly decapsulate and forward other unexpected tunneled packets with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel t [truncated]

MEDIUM Arista Networks CVE published 2026-06-05

CVE-2026-25624

CVE-2026-25624 is a MEDIUM severity vulnerability in Arista Edge Threat Management - Arista Next Generation Firewall. An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout. Unvalidated user-supplied variables are echoed back to administrative profiles, facilitating vector payload processing behavior controls.

HIGH Arista Networks CVE published 2026-06-05

CVE-2026-25623

CVE-2026-25623 is a HIGH severity vulnerability in Arista Edge Threat Management - Arista Next Generation Firewall . An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators can leverage this exposure to obtain underlying terminal script code processing execution permissions.

HIGH Arista Networks CVE published 2026-06-05

CVE-2026-25622

CVE-2026-25622 is a HIGH severity vulnerability with a CVSS score of 7. An administrative account logged into the user interface can exploit this input handling behavior to execute arbitrary platform shell commands.

HIGH Arista Networks CVE published 2026-06-05

CVE-2026-25621

CVE-2026-25621 is a HIGH severity vulnerability in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). The vulnerability exists due to insecure input validation in the Reports application infrastructure, affecting version 17.4.0. Earlier software releases are not exposed. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.0.

HIGH Arista Networks CVE published 2026-06-05

CVE-2026-25620

An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely affects version 17.4.0; earlier software releases are not exposed. The vulnerability has a CVSS score of 7 and is classified as HIGH.

HIGH Arista Networks CVE published 2026-06-05

CVE-2026-2379

CVE-2026-2379 is a HIGH severity vulnerability in Arista EOS with a CVSS score of 8.2. On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting in sequence number mi [truncated]

HIGH Arista Networks CVE published 2026-06-05

CVE-2025-5090

A high-severity vulnerability was discovered in CVX, which could lead to a denial-of-service (DoS) scenario. An attacker with high privilege access to a connected switch could send custom TCP packets to CVX, causing agent crashes and instability in the CVX cluster.

HIGH Arista Networks CVE published 2026-06-05

CVE-2025-5088

CVE-2025-5088 is a HIGH-severity vulnerability with a CVSS score of 8.7. An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. This requires network access to the Redis service on a CVX server and the Redis password. Note that all Redis communication, including authentication, occurs over plaintext. TLS support is tracked under RFE1294850.

HIGH Arista Networks CVE published 2026-06-04

CVE-2025-8873

CVE-2025-8873 is a HIGH severity vulnerability in Arista EOS with IPsec configured. A specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition and attempt to reset the IPsec processing pipeline. After reset, traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or termina [truncated]

HIGH Arista Networks CVE published 2026-06-04

CVE-2024-27892

CVE-2024-27892 is a HIGH-severity vulnerability affecting Arista EOS with OpenConfig configured. A gNMI Set request can be run when it should have been rejected, resulting in unexpected configuration being applied to the switch. The CVSS score for this vulnerability is 7.2.

MEDIUM Arista Networks CVE published 2026-06-04

CVE-2024-27891

On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.

HIGH Arista Networks CVE published 2026-06-04

CVE-2024-27890

CVE-2024-27890 is a HIGH-severity vulnerability affecting Arista EOS with OpenConfig configured. A gNMI Set request can be run when it should have been rejected, resulting in unexpected configuration being applied to the switch. The CVSS score for this vulnerability is 7.2.

HIGH Arista Networks CVE published 2026-06-04

CVE-2023-5502

CVE-2023-5502 is a HIGH severity vulnerability in Arista EOS with 802.1x authentication configured on access/trunk ports and routing enabled on the access VLAN. A malicious supplicant may bypass 802.1x authentication requirements. The vulnerability has a CVSS score of 8.2.

MEDIUM Arista Networks CVE published 2026-06-04

CVE-2024-6858

CVE-2024-6858 is a MEDIUM severity vulnerability in Arista's EOS when in 802.1X mode. The vulnerability allows multi-auth unauthenticated hosts to access a switch port if there exists an EAPOL capable device in the fallback VLAN. The CVSS score for this vulnerability is 6.5.