Arista kayıtları
arista üreticisine ait 105 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 6 · %5,7
- Silahlaştırılmış
- 7 · %6,7
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %28,6
- Yayından KEV’e ortanca
- 7 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')8
- CWE-284 Improper Access Control6
- CWE-287 Improper Authentication6
- CWE-20 Improper Input Validation4
- CWE-255 Credentials Management Errors4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
105 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
70Bu hafta | CVE-2026-16812Silahlaştırılmış | VeloCloud Orchestrator OS Command Injectionarista · velocloud orchestrator · CWE-78 | Kritik10,0 | KEV | %1,0 | 27 Tem 2026 |
68Bu hafta | CVE-2026-93952Silahlaştırılmış | Security Advisory 0183arista · velocloud orchestrator · CWE-20 | Kritik9,5 | KEV | %1,1 | 22 Eyl 2026 |
64Bu hafta | CVE-2017-14491Kavram kanıtı | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Kritik9,8 | — | %84,9 | 3 Eki 2017 |
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2026-31431Silahlaştırılmış | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | Yüksek7,8 | KEV | %3,4 | 22 Nis 2026 |
61Bu hafta | CVE-2020-10188İstismar yok | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Kritik9,8 | — | %74,3 | 6 Mar 2020 |
57Planlayın | CVE-2026-7473Silahlaştırılmış | Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypassarista · eos · CWE-1023 | Orta6,9 | KEV | %0,6 | 5 Haz 2026 |
55Planlayın | CVE-2017-18017İstismar yok | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Kritik9,8 | — | %52,8 | 3 Oca 2018 |
44Planlayın | CVE-2020-9015Silahlaştırılmış | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow aarista · dcs-7050qx-32s-r firmware | Kritik9,8 | — | %16,5 | 20 Şub 2020 |
41Planlayın | CVE-2015-5165İstismar yok | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers toxen · xen · CWE-908 | Kritik9,3 | — | %13,3 | 12 Ağu 2015 |
41Planlayın | CVE-2015-8236İstismar yok | Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attaarista · eos · CWE-264 | Kritik10,0 | — | %4,2 | 19 Kas 2015 |
39İzleyin | CVE-2021-28495İstismar yok | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatarista · metamako operating system · CWE-287 | Kritik9,8 | — | %0,9 | 9 Eyl 2021 |
39İzleyin | CVE-2021-28503İstismar yok | In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote atarista · eos · CWE-305 | Kritik9,8 | — | %0,7 | 4 Şub 2022 |
39İzleyin | CVE-2024-9132İstismar yok | The administrator is able to configure an insecure captive portal scriptarista · ng firewall · CWE-94 | Kritik9,8 | — | %0,7 | 10 Oca 2025 |
38İzleyin | CVE-2024-27889İstismar yok | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).arista · ng firewall · CWE-89 | Yüksek8,8 | — | %8,8 | 4 Mar 2024 |
38İzleyin | CVE-2025-2767İstismar yok | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerabilityarista · ng firewall · CWE-79 | Kritik9,6 | — | %0,6 | 23 Nis 2025 |
36İzleyin | CVE-2021-28506İstismar yok | An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a faarista · eos · CWE-285 | Kritik9,1 | — | %1,4 | 14 Oca 2022 |
35İzleyin | CVE-2016-9012İstismar yok | CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via thearista · cloudvision portal · CWE-264 | Yüksek8,8 | — | %1,5 | 23 Oca 2017 |
35İzleyin | CVE-2024-12829İstismar yok | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerabilityarista · ng firewall · CWE-78 | Yüksek8,8 | — | %1,3 | 19 Ara 2024 |
35İzleyin | CVE-2020-3973İstismar yok | The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.arista · velocloud orchestrator · CWE-89 | Yüksek8,8 | — | %1,1 | 8 Tem 2020 |
35İzleyin | CVE-2021-28494İstismar yok | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iarista · metamako operating system · CWE-287 | Yüksek8,8 | — | %0,9 | 9 Eyl 2021 |
35İzleyin | CVE-2024-9188İstismar yok | Specially constructed queries cause cross platform scripting leaking administrator tokensarista · ng firewall · CWE-79 | Yüksek8,8 | — | %0,5 | 10 Oca 2025 |
33İzleyin | CVE-2015-3209İstismar yok | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATqemu · qemu · CWE-787 | Yüksek7,5 | — | %9,7 | 15 Haz 2015 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2026-1681270Bu hafta
VeloCloud Orchestrator OS Command Injection
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1arista · velocloud orchestrator27 Tem 2026
- CVE-2026-9395268Bu hafta
Security Advisory 0183
KritikCVSS 9,5KEVSilahlaştırılmışEPSS %1arista · velocloud orchestrator22 Eyl 2026
- CVE-2017-1449164Bu hafta
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
KritikCVSS 9,8Kavram kanıtıEPSS %85thekelleys · dnsmasq3 Eki 2017
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2026-3143162Bu hafta
crypto: algif_aead - Revert to operating out-of-place
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3linux · linux kernel22 Nis 2026
- CVE-2020-1018861Bu hafta
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
KritikCVSS 9,8İstismar yokEPSS %74netkit telnet project · netkit telnet6 Mar 2020
- CVE-2026-747357Planlayın
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1arista · eos5 Haz 2026
- CVE-2017-1801755Planlayın
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
KritikCVSS 9,8İstismar yokEPSS %53linux · linux kernel3 Oca 2018
- CVE-2020-901544Planlayın
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a
KritikCVSS 9,8SilahlaştırılmışEPSS %16arista · dcs-7050qx-32s-r firmware20 Şub 2020
- CVE-2015-516541Planlayın
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to
KritikCVSS 9,3İstismar yokEPSS %13xen · xen12 Ağu 2015
- CVE-2015-823641Planlayın
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta
KritikCVSS 10,0İstismar yokEPSS %4arista · eos19 Kas 2015
- CVE-2021-2849539İzleyin
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat
KritikCVSS 9,8İstismar yokEPSS %1arista · metamako operating system9 Eyl 2021
- CVE-2021-2850339İzleyin
In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at
KritikCVSS 9,8İstismar yokEPSS %1arista · eos4 Şub 2022
- CVE-2024-913239İzleyin
The administrator is able to configure an insecure captive portal script
KritikCVSS 9,8İstismar yokEPSS %1arista · ng firewall10 Oca 2025
- CVE-2024-2788938İzleyin
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).
YüksekCVSS 8,8İstismar yokEPSS %9arista · ng firewall4 Mar 2024
- CVE-2025-276738İzleyin
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability
KritikCVSS 9,6İstismar yokEPSS %1arista · ng firewall23 Nis 2025
- CVE-2021-2850636İzleyin
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa
KritikCVSS 9,1İstismar yokEPSS %1arista · eos14 Oca 2022
- CVE-2016-901235İzleyin
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the
YüksekCVSS 8,8İstismar yokEPSS %2arista · cloudvision portal23 Oca 2017
- CVE-2024-1282935İzleyin
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1arista · ng firewall19 Ara 2024
- CVE-2020-397335İzleyin
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.
YüksekCVSS 8,8İstismar yokEPSS %1arista · velocloud orchestrator8 Tem 2020
- CVE-2021-2849435İzleyin
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i
YüksekCVSS 8,8İstismar yokEPSS %1arista · metamako operating system9 Eyl 2021
- CVE-2024-918835İzleyin
Specially constructed queries cause cross platform scripting leaking administrator tokens
YüksekCVSS 8,8İstismar yokEPSS %0arista · ng firewall10 Oca 2025
- CVE-2015-320933İzleyin
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT
YüksekCVSS 7,5İstismar yokEPSS %10qemu · qemu15 Haz 2015