Vulnerabilities > Arista > EOS > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-08-29 CVE-2023-24548 Classic Buffer Overflow vulnerability in Arista EOS
On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel and forwarded in hardware can cause egress ports to be unable to forward packets.
low complexity
arista CWE-120
6.5
2023-04-25 CVE-2023-24512 Incorrect Authorization vulnerability in Arista products
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch.
network
low complexity
arista CWE-863
6.5
2022-08-05 CVE-2021-28511 Unspecified vulnerability in Arista EOS
This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass.
network
low complexity
arista
6.5
2022-05-26 CVE-2021-28508 Cleartext Transmission of Sensitive Information vulnerability in Arista EOS and Terminattr
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols.
network
low complexity
arista CWE-319
6.1
2022-05-26 CVE-2021-28509 Cleartext Transmission of Sensitive Information vulnerability in Arista EOS and Terminattr
This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent TerminAttr and OpenConfig transport protocols.
network
low complexity
arista CWE-319
6.1
2021-10-21 CVE-2021-28496 Insufficiently Protected Credentials vulnerability in Arista EOS
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device.
network
low complexity
arista CWE-522
6.5
2020-12-28 CVE-2020-15898 Unspecified vulnerability in Arista EOS
In Arista EOS malformed packets can be incorrectly forwarded across VLAN boundaries in one direction.
network
low complexity
arista
5.3
2020-12-28 CVE-2020-26569 Unspecified vulnerability in Arista EOS
In EVPN VxLAN setups in Arista EOS, specific malformed packets can lead to incorrect MAC to IP bindings and as a result packets can be incorrectly forwarded across VLAN boundaries.
network
high complexity
arista
5.9
2020-01-23 CVE-2015-5745 Classic Buffer Overflow vulnerability in multiple products
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
network
low complexity
qemu fedoraproject arista CWE-120
6.5
2020-01-23 CVE-2015-5278 Infinite Loop vulnerability in multiple products
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.
network
low complexity
qemu fedoraproject canonical arista CWE-835
6.5