📦 Eos

by Arista

🔍 What is Eos?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24509

CRITICAL CVSS 9.3 Apr 13, 2023

This vulnerability allows an existing unprivileged user with valid credentials to log into the standby supervisor module as root, leading to privilege escalation on affected Arista EOS platforms. It a...

CVE-2021-28500

CRITICAL CVSS 9.1 Jan 14, 2022

This vulnerability in Arista EOS allows local users with 'nopassword' configuration to gain unrestricted access to network devices due to incorrect AAA API usage by OpenConfig and TerminAttr agents. I...

CVE-2021-28506

CRITICAL CVSS 9.1 Jan 14, 2022

CVE-2021-28506 is an authentication bypass vulnerability in Arista EOS gNOI APIs that allows unauthorized factory resets of network devices. This affects Arista EOS users with gNOI APIs enabled. Attac...

CVE-2023-24510

HIGH CVSS 7.5 Jun 5, 2023

This vulnerability in Arista EOS DHCP relay agent allows an attacker to cause a denial of service by sending a malformed DHCP packet, leading to the agent restarting. It affects Arista switches and ro...

CVE-2023-24512

HIGH CVSS 8.8 Apr 25, 2023

This vulnerability allows authenticated attackers with gNMI access to modify arbitrary configurations on Arista EOS switches when the Streaming Telemetry Agent (TerminAttr) is enabled with gNMI config...

CVE-2021-28505

HIGH CVSS 7.5 Apr 14, 2022

This vulnerability in Arista EOS platforms allows VXLAN match rules in IPv4 access-lists to ignore specified IP protocols when applied to L2/L3 port ingress. This can lead to unintended traffic being ...

CVE-2021-28503

HIGH CVSS 7.4 Feb 4, 2022

Arista EOS eAPI authentication bypass vulnerability allows remote attackers to access network devices without proper credential validation when certificate-based authentication is enabled. This affect...