Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.24% | — | Arista EOS | 13/4/2023 | 17/6/2026 | On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in… | |
| Modificada | Alta (7.5) | 0.78% | — | Arista Cloudeos | 12/4/2023 | 17/6/2026 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding… | |
| Modificada | Alta (7.5) | 0.84% | — | Arista EOS | 12/4/2023 | 17/6/2026 | On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other… | |
| Modificada | Alta (7.5) | 0.68% | — | Arista Cloudeos | 12/4/2023 | 17/6/2026 | On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding… | |
| Modificada | Alta (7.5) | 1.0% | — | Arista EOS | 26/1/2023 | 17/6/2026 | For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable. | |
| Modificada | Media (5.5) | 0.20% | — | Arista Cloudvision Portal | 5/8/2022 | 17/6/2026 | This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to… | |
| Modificada | Media (6.5) | 0.58% | — | Arista EOS | 5/8/2022 | 17/6/2026 | This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range… | |
| Modificada | Media (6.1) | 0.46% | — | Arista TerminattrArista EOS | 26/5/2022 | 17/6/2026 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak MACsec sensitive data in clear text in CVP to other authorized… | |
| Modificada | Media (6.1) | 0.51% | — | Arista TerminattrArista EOS | 26/5/2022 | 17/6/2026 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols. The impact of this vulnerability is that, in certain conditions, TerminAttr might leak IPsec sensitive data in clear text in CVP to other authorized… | |
| Modificada | Alta (7.5) | 0.88% | — | Arista EOS | 14/4/2022 | 17/6/2026 | On affected Arista EOS platforms, if a VXLAN match rule exists in an IPv4 access-list that is applied to the ingress of an L2 or an L3 port/SVI, the VXLAN rule and subsequent ACL rules in that access list will ignore the specified IP protocol. | |
| Modificada | Alta (7.5) | 0.73% | — | Arista EOS | 1/4/2022 | 17/6/2026 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected. | |
| Modificada | Crítica (9.8) | 0.73% | — | Arista EOS | 4/2/2022 | 17/6/2026 | The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI. | |
| Modificada | Alta (7.1) | 0.67% | — | Arista EOS | 14/1/2022 | 17/6/2026 | An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent. | |
| Modificada | Crítica (9.1) | 1.4% | — | Arista EOS | 14/1/2022 | 17/6/2026 | An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device. | |
| Modificada | Alta (7.8) | 0.84% | — | Arista Terminattr | 14/1/2022 | 17/6/2026 | An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration. | |
| Modificada | Alta (7.8) | 0.81% | — | Arista EOS | 14/1/2022 | 17/6/2026 | An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration. | |
| Modificada | Media (6.5) | 0.43% | — | Arista EOS | 21/10/2021 | 17/6/2026 | On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS… | |
| Modificada | Media (5.5) | 0.21% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user account passwords set in clear text could leak to users without any password. This issue affects: Arista Metamako Operating System MOS-0.18 and post releases in the MOS-0.1x train All releases in the MOS-0.2x train… | |
| Modificada | Alta (7.8) | 0.22% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords set in clear text could result in unprivileged users getting complete access to the systems. This issue affects: Arista Metamako Operating System MOS-0.13 and post releases in the MOS-0.1x train… | |
| Modificada | Alta (7.8) | 0.23% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, the bash shell might be accessible to unprivileged users in situations where they should not have access. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train… | |
| Modificada | Crítica (9.8) | 0.93% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authentication can be bypassed when API access is enabled via the JSON-RPC APIs. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.13 and post… | |
| Modificada | Alta (8.8) | 0.88% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases | |
| Modificada | Alta (7.8) | 0.22% | — | Arista Metamako Operating System | 9/9/2021 | 17/6/2026 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior… | |
| Modificada | Media (5.4) | 7.6% | — | Linux KernelDebian LinuxArista C-75 FirmwareArista O-90 Firmware+4 | 11/5/2021 | 17/6/2026 | An issue was discovered in the Linux kernel 5.8.9. The WEP, WPA, WPA2, and WPA3 implementations reassemble fragments even though some of them were sent in plaintext. This vulnerability can be abused to inject packets and/or exfiltrate selected fragments when another device sends fragmented frames and the WEP, CCMP, or… | |
| Modificada | Media (5.3) | 5.6% | — | Samsung Galaxy I9305 FirmwareArista C-250 FirmwareArista C-260 FirmwareArista C-230 Firmware+15 | 11/5/2021 | 17/6/2026 | An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP,… |