Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.6) | 0.17% | — | Arista EOSAI | 14/11/2025 | 17/6/2026 | On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153 | |
| Aplazada | Media (6.5) | 0.26% | — | Arista Aos-8 InstantAIArista AOS 10AI | 14/10/2025 | 17/6/2026 | A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality. | |
| Aplazada | Alta (7.5) | 0.42% | — | Arista EOSAI | 25/8/2025 | 17/6/2026 | On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. UDP Port 3503 is associated with LspPing Echo Reply. This can result in unexpected behaviors, especially for UDP based services that do not perform some form of authentication. | |
| Aplazada | Baja (3.8) | 0.10% | — | Arista EOSAI | 25/8/2025 | 17/6/2026 | On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords… | |
| Aplazada | Baja (2.6) | 0.52% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or… | |
| Aplazada | Media (5.3) | 0.19% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this… | |
| Aplazada | Media (6.5) | 0.26% | — | Arista EOSAI | 27/5/2025 | 17/6/2026 | On affected platforms running Arista EOS, ingress traffic on Layer 2 ports may, under certain conditions, be improperly forwarded to ports associated with different VLANs, resulting in a breach of VLAN isolation and segmentation boundaries. | |
| Aplazada | Alta (7.5) | 0.59% | — | Arista EOSAI | 8/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in… | |
| Aplazada | Crítica (10) | 0.66% | — | Arista CloudvisionAI | 8/5/2025 | 17/6/2026 | On Arista CloudVision systems (virtual or physical on-premise deployments), Zero Touch Provisioning can be used to gain admin privileges on the CloudVision system, with more permissions than necessary, which can be used to query or manipulate system state for devices under management. Note that CloudVision… | |
| Aplazada | Alta (8.7) | 0.63% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Arista EOSAI | 8/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear. | |
| Aplazada | Crítica (10) | 0.78% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service. | |
| Aplazada | Media (6.5) | 0.28% | — | Arista EOSAI | 7/5/2025 | 17/6/2026 | On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc). | |
| Analizada | Crítica (9.6) | 0.64% | — | Arista NG Firewall | 23/4/2025 | 17/6/2026 | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Minimal user interaction is required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Media (6) | 0.25% | — | Arista Aos-8 InstantAIArista Aos-10 APAI | 8/4/2025 | 17/6/2026 | A vulnerability in the file creation process on the command line interface of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to perform remote code execution (RCE). Successful exploitation could allow an attacker to execute arbitrary operating system commands on the underlying operating… | |
| Aplazada | Media (5.3) | 0.36% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping. | |
| Aplazada | Media (5.3) | 0.20% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart. Note: supplicants with pending captive-portal authentication… | |
| Aplazada | Crítica (9.1) | 0.44% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch. | |
| Aplazada | Alta (7.7) | 0.35% | — | Arista EOSAI | 4/3/2025 | 17/6/2026 | On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available | |
| Analizada | Alta (8.8) | 0.48% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Specially constructed queries cause cross platform scripting leaking administrator tokens | |
| Analizada | Alta (8.3) | 0.62% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges. | |
| Analizada | Media (5.6) | 0.16% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with administrator privileges is able to retrieve authentication tokens | |
| Analizada | Crítica (9.8) | 0.69% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | The administrator is able to configure an insecure captive portal script | |
| Analizada | Alta (7.2) | 1.4% | — | Arista NG Firewall | 10/1/2025 | 17/6/2026 | A user with administrator privileges can perform command injection | |
| Aplazada | Media (4.6) | 0.10% | — | Arista Cloudvision ApplianceAIArista Dca-350e-cvAI | 10/1/2025 | 17/6/2026 | On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them |