« Volver al listado

Arista

Arista EOS: vulnerabilidades y CVE

Arista EOS tiene 108 vulnerabilidades publicadas, 48 de ellas en los últimos 12 meses. 14 son críticas y 3 figuran en el catálogo de explotación activa de CISA.

CVE108
Últimos 12 meses48
Críticas14
Explotadas activamente3

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-7473Media (6.9)0.65%⚠ Explotación activa5 jun 2026
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch…
CVE-2014-7169Crítica (9.8)100%⚠ Explotación activa25 sept 2014
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown…
CVE-2014-6271Crítica (9.8)100%⚠ Explotación activa24 sept 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73462Alta (7.1)0.28%—16 sept 2026
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network…
CVE-2026-73457Media (6)0.32%—16 sept 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting…
CVE-2026-73456Crítica (9.2)0.69%—16 sept 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code…
CVE-2026-73443Media (5.3)0.27%—16 sept 2026
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated…
CVE-2026-73442Baja (2.1)0.21%—16 sept 2026
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent…
CVE-2026-77190Media (6)0.28%—16 sept 2026
On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that…
CVE-2026-73469Media (6.9)0.29%—16 sept 2026
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should…
CVE-2026-73455Alta (8.9)0.50%—16 sept 2026
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
CVE-2026-73453Crítica (9.5)0.69%—16 sept 2026
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with…
CVE-2026-73440Baja (2.3)0.27%—16 sept 2026
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's…
CVE-2026-73438Alta (7)0.25%—16 sept 2026
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can…
CVE-2026-73436Media (6)0.27%—16 sept 2026
On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
CVE-2026-73435Alta (7)0.19%—16 sept 2026
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2…
CVE-2026-19640Baja (2.3)0.19%—16 sept 2026
On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently…
CVE-2026-73464Alta (8.7)0.64%—16 sept 2026
On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI)…
CVE-2026-73463Media (6)0.21%—16 sept 2026
On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An…
CVE-2026-73461Crítica (9.4)0.39%—16 sept 2026
On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong…
CVE-2026-73454Alta (8.6)0.39%—16 sept 2026
On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may…
CVE-2026-73445Media (6.9)0.35%—16 sept 2026
On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This…
CVE-2026-73439Alta (7.7)0.36%—16 sept 2026
On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is configured and a gNSI Pathz policy is present on the system, then gNMI may fail to…
CVE-2026-2380Media (5.1)0.25%—16 sept 2026
On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS…
CVE-2026-73447Crítica (9.4)0.70%—16 sept 2026
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz…
CVE-2026-73450Alta (7)0.16%—16 sept 2026
On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere…
CVE-2026-73460Alta (7)0.20%—16 sept 2026
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate…
CVE-2026-73459Alta (7)0.17%—16 sept 2026
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS…
CVE-2026-73446Alta (7)0.27%—16 sept 2026
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an…
CVE-2026-73444Media (5.3)0.30%—15 sept 2026
On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could…
CVE-2026-73437Media (6.5)0.21%—15 sept 2026
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that…
CVE-2026-19655Alta (7.1)0.19%—15 sept 2026
On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on…
CVE-2026-73458Crítica (9.2)0.40%—15 sept 2026
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in…

Otros productos de Arista