Vulnerabilities > Arista > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-08-15 CVE-2018-12357 Incorrect Permission Assignment for Critical Resource vulnerability in Arista Cloudvision Portal
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
network
low complexity
arista CWE-732
4.0
2018-04-12 CVE-2018-5254 Channel and Path Errors vulnerability in Arista EOS
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
network
low complexity
arista CWE-417
5.0
2018-03-05 CVE-2018-5255 Unspecified vulnerability in Arista EOS
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
network
low complexity
arista
4.0
2017-01-23 CVE-2016-9012 Permissions, Privileges, and Access Controls vulnerability in Arista Cloudvision Portal
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
network
low complexity
arista CWE-264
6.5
2015-11-06 CVE-2015-6855 Divide By Zero vulnerability in multiple products
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
5.0