İçeriğe atla
Noroxi

Arista kayıtları

arista üreticisine ait 105 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
6 · %5,7
Silahlaştırılmış
7 · %6,7
Pre-auth RCE
11
Düzeltme kaydı olan
%28,6
Yayından KEV’e ortanca
7 gün

Tüm kayıtlar

105 kayıt
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • CVE-2026-16812
    70Bu hafta

    VeloCloud Orchestrator OS Command Injection

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %1

    arista · velocloud orchestrator27 Tem 2026

  • CVE-2026-93952
    68Bu hafta

    Security Advisory 0183

    KritikCVSS 9,5KEVSilahlaştırılmışEPSS %1

    arista · velocloud orchestrator22 Eyl 2026

  • CVE-2017-14491
    64Bu hafta

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via

    KritikCVSS 9,8Kavram kanıtıEPSS %85

    thekelleys · dnsmasq3 Eki 2017

  • CVE-2024-6387
    62Bu hafta

    Openssh: regresshion - race condition in ssh allows rce/dos

    YüksekCVSS 8,1Kavram kanıtıEPSS %100

    sonicwall · sma 6200 firmware1 Tem 2024

  • CVE-2026-31431
    62Bu hafta

    crypto: algif_aead - Revert to operating out-of-place

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3

    linux · linux kernel22 Nis 2026

  • CVE-2020-10188
    61Bu hafta

    utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus

    KritikCVSS 9,8İstismar yokEPSS %74

    netkit telnet project · netkit telnet6 Mar 2020

  • CVE-2026-7473
    57Planlayın

    Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass

    OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1

    arista · eos5 Haz 2026

  • CVE-2017-18017
    55Planlayın

    The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac

    KritikCVSS 9,8İstismar yokEPSS %53

    linux · linux kernel3 Oca 2018

  • CVE-2020-9015
    44Planlayın

    Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a

    KritikCVSS 9,8SilahlaştırılmışEPSS %16

    arista · dcs-7050qx-32s-r firmware20 Şub 2020

  • CVE-2015-5165
    41Planlayın

    The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to

    KritikCVSS 9,3İstismar yokEPSS %13

    xen · xen12 Ağu 2015

  • CVE-2015-8236
    41Planlayın

    Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta

    KritikCVSS 10,0İstismar yokEPSS %4

    arista · eos19 Kas 2015

  • CVE-2021-28495
    39İzleyin

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat

    KritikCVSS 9,8İstismar yokEPSS %1

    arista · metamako operating system9 Eyl 2021

  • CVE-2021-28503
    39İzleyin

    In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at

    KritikCVSS 9,8İstismar yokEPSS %1

    arista · eos4 Şub 2022

  • CVE-2024-9132
    39İzleyin

    The administrator is able to configure an insecure captive portal script

    KritikCVSS 9,8İstismar yokEPSS %1

    arista · ng firewall10 Oca 2025

  • CVE-2024-27889
    38İzleyin

    Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).

    YüksekCVSS 8,8İstismar yokEPSS %9

    arista · ng firewall4 Mar 2024

  • CVE-2025-2767
    38İzleyin

    Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability

    KritikCVSS 9,6İstismar yokEPSS %1

    arista · ng firewall23 Nis 2025

  • CVE-2021-28506
    36İzleyin

    An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa

    KritikCVSS 9,1İstismar yokEPSS %1

    arista · eos14 Oca 2022

  • CVE-2016-9012
    35İzleyin

    CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the

    YüksekCVSS 8,8İstismar yokEPSS %2

    arista · cloudvision portal23 Oca 2017

  • CVE-2024-12829
    35İzleyin

    Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    arista · ng firewall19 Ara 2024

  • CVE-2020-3973
    35İzleyin

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.

    YüksekCVSS 8,8İstismar yokEPSS %1

    arista · velocloud orchestrator8 Tem 2020

  • CVE-2021-28494
    35İzleyin

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i

    YüksekCVSS 8,8İstismar yokEPSS %1

    arista · metamako operating system9 Eyl 2021

  • CVE-2024-9188
    35İzleyin

    Specially constructed queries cause cross platform scripting leaking administrator tokens

    YüksekCVSS 8,8İstismar yokEPSS %0

    arista · ng firewall10 Oca 2025

  • CVE-2015-3209
    33İzleyin

    Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT

    YüksekCVSS 7,5İstismar yokEPSS %10

    qemu · qemu15 Haz 2015