Vulnerabilities > Arista > High

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-9012 Permissions, Privileges, and Access Controls vulnerability in Arista Cloudvision Portal
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
network
low complexity
arista CWE-264
8.8
2017-01-04 CVE-2016-6894 Resource Management Errors vulnerability in Arista products
Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of service (device reboot) by sending crafted packets to the control plane.
network
low complexity
arista CWE-399
7.5
2015-11-06 CVE-2015-6855 Divide By Zero vulnerability in multiple products
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
7.5