Vulnerabilities > Arista > EOS > High

DATE CVE VULNERABILITY TITLE RISK
2020-10-26 CVE-2020-15897 Unspecified vulnerability in Arista EOS
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.
network
low complexity
arista
7.5
2020-10-21 CVE-2020-17355 Unspecified vulnerability in Arista EOS
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
network
low complexity
arista
7.5
2020-04-16 CVE-2019-18948 Unspecified vulnerability in Arista EOS
An issue was found in Arista EOS.
network
low complexity
arista
7.5
2019-10-24 CVE-2019-17596 Interpretation Conflict vulnerability in multiple products
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key.
7.5
2018-04-12 CVE-2018-5254 Channel and Path Errors vulnerability in Arista EOS
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
network
low complexity
arista CWE-417
7.5
2015-11-06 CVE-2015-6855 Divide By Zero vulnerability in multiple products
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
7.5