arista records
105 published records for vendor arista.
Researcher profile
- Entered KEV
- 6 · 5.7%
- Weaponized
- 7 · 6.7%
- Pre-auth RCE
- 11
- With a fix record
- 28.6%
- Median publish → KEV
- 7 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')8
- CWE-284 Improper Access Control6
- CWE-287 Improper Authentication6
- CWE-20 Improper Input Validation4
- CWE-255 Credentials Management Errors4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
105 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
70This week | CVE-2026-16812Weaponized | VeloCloud Orchestrator OS Command Injectionarista · velocloud orchestrator · CWE-78 | Critical10.0 | KEV | 1.0% | Jul 27, 2026 |
68This week | CVE-2026-93952Weaponized | Security Advisory 0183arista · velocloud orchestrator · CWE-20 | Critical9.5 | KEV | 1.1% | Sep 22, 2026 |
64This week | CVE-2017-14491Proof of concept | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Critical9.8 | — | 84.9% | Oct 3, 2017 |
62This week | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | High8.1 | — | 99.5% | Jul 1, 2024 |
62This week | CVE-2026-31431Weaponized | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | High7.8 | KEV | 3.4% | Apr 22, 2026 |
61This week | CVE-2020-10188No exploit | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Critical9.8 | — | 74.3% | Mar 6, 2020 |
57Plan | CVE-2026-7473Weaponized | Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypassarista · eos · CWE-1023 | Medium6.9 | KEV | 0.6% | Jun 5, 2026 |
55Plan | CVE-2017-18017No exploit | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Critical9.8 | — | 52.8% | Jan 3, 2018 |
44Plan | CVE-2020-9015Weaponized | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow aarista · dcs-7050qx-32s-r firmware | Critical9.8 | — | 16.5% | Feb 20, 2020 |
41Plan | CVE-2015-5165No exploit | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers toxen · xen · CWE-908 | Critical9.3 | — | 13.3% | Aug 12, 2015 |
41Plan | CVE-2015-8236No exploit | Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attaarista · eos · CWE-264 | Critical10.0 | — | 4.2% | Nov 19, 2015 |
39Monitor | CVE-2021-28495No exploit | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatarista · metamako operating system · CWE-287 | Critical9.8 | — | 0.9% | Sep 9, 2021 |
39Monitor | CVE-2021-28503No exploit | In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote atarista · eos · CWE-305 | Critical9.8 | — | 0.7% | Feb 4, 2022 |
39Monitor | CVE-2024-9132No exploit | The administrator is able to configure an insecure captive portal scriptarista · ng firewall · CWE-94 | Critical9.8 | — | 0.7% | Jan 10, 2025 |
38Monitor | CVE-2024-27889No exploit | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).arista · ng firewall · CWE-89 | High8.8 | — | 8.8% | Mar 4, 2024 |
38Monitor | CVE-2025-2767No exploit | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerabilityarista · ng firewall · CWE-79 | Critical9.6 | — | 0.6% | Apr 23, 2025 |
36Monitor | CVE-2021-28506No exploit | An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a faarista · eos · CWE-285 | Critical9.1 | — | 1.4% | Jan 14, 2022 |
35Monitor | CVE-2016-9012No exploit | CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via thearista · cloudvision portal · CWE-264 | High8.8 | — | 1.5% | Jan 23, 2017 |
35Monitor | CVE-2024-12829No exploit | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerabilityarista · ng firewall · CWE-78 | High8.8 | — | 1.3% | Dec 19, 2024 |
35Monitor | CVE-2020-3973No exploit | The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.arista · velocloud orchestrator · CWE-89 | High8.8 | — | 1.1% | Jul 8, 2020 |
35Monitor | CVE-2021-28494No exploit | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iarista · metamako operating system · CWE-287 | High8.8 | — | 0.9% | Sep 9, 2021 |
35Monitor | CVE-2024-9188No exploit | Specially constructed queries cause cross platform scripting leaking administrator tokensarista · ng firewall · CWE-79 | High8.8 | — | 0.5% | Jan 10, 2025 |
33Monitor | CVE-2015-3209No exploit | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATqemu · qemu · CWE-787 | High7.5 | — | 9.7% | Jun 15, 2015 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2026-1681270This week
VeloCloud Orchestrator OS Command Injection
CriticalCVSS 10.0KEVWeaponizedEPSS 1%arista · velocloud orchestratorJul 27, 2026
- CVE-2026-9395268This week
Security Advisory 0183
CriticalCVSS 9.5KEVWeaponizedEPSS 1%arista · velocloud orchestratorSep 22, 2026
- CVE-2017-1449164This week
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
CriticalCVSS 9.8Proof of conceptEPSS 85%thekelleys · dnsmasqOct 3, 2017
- CVE-2024-638762This week
Openssh: regresshion - race condition in ssh allows rce/dos
HighCVSS 8.1Proof of conceptEPSS 100%sonicwall · sma 6200 firmwareJul 1, 2024
- CVE-2026-3143162This week
crypto: algif_aead - Revert to operating out-of-place
HighCVSS 7.8KEVWeaponizedEPSS 3%linux · linux kernelApr 22, 2026
- CVE-2020-1018861This week
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
CriticalCVSS 9.8No exploitEPSS 74%netkit telnet project · netkit telnetMar 6, 2020
- CVE-2026-747357Plan
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
MediumCVSS 6.9KEVWeaponizedEPSS 1%arista · eosJun 5, 2026
- CVE-2017-1801755Plan
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
CriticalCVSS 9.8No exploitEPSS 53%linux · linux kernelJan 3, 2018
- CVE-2020-901544Plan
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a
CriticalCVSS 9.8WeaponizedEPSS 16%arista · dcs-7050qx-32s-r firmwareFeb 20, 2020
- CVE-2015-516541Plan
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to
CriticalCVSS 9.3No exploitEPSS 13%xen · xenAug 12, 2015
- CVE-2015-823641Plan
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta
CriticalCVSS 10.0No exploitEPSS 4%arista · eosNov 19, 2015
- CVE-2021-2849539Monitor
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat
CriticalCVSS 9.8No exploitEPSS 1%arista · metamako operating systemSep 9, 2021
- CVE-2021-2850339Monitor
In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at
CriticalCVSS 9.8No exploitEPSS 1%arista · eosFeb 4, 2022
- CVE-2024-913239Monitor
The administrator is able to configure an insecure captive portal script
CriticalCVSS 9.8No exploitEPSS 1%arista · ng firewallJan 10, 2025
- CVE-2024-2788938Monitor
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).
HighCVSS 8.8No exploitEPSS 9%arista · ng firewallMar 4, 2024
- CVE-2025-276738Monitor
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability
CriticalCVSS 9.6No exploitEPSS 1%arista · ng firewallApr 23, 2025
- CVE-2021-2850636Monitor
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa
CriticalCVSS 9.1No exploitEPSS 1%arista · eosJan 14, 2022
- CVE-2016-901235Monitor
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the
HighCVSS 8.8No exploitEPSS 2%arista · cloudvision portalJan 23, 2017
- CVE-2024-1282935Monitor
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%arista · ng firewallDec 19, 2024
- CVE-2020-397335Monitor
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.
HighCVSS 8.8No exploitEPSS 1%arista · velocloud orchestratorJul 8, 2020
- CVE-2021-2849435Monitor
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i
HighCVSS 8.8No exploitEPSS 1%arista · metamako operating systemSep 9, 2021
- CVE-2024-918835Monitor
Specially constructed queries cause cross platform scripting leaking administrator tokens
HighCVSS 8.8No exploitEPSS 0%arista · ng firewallJan 10, 2025
- CVE-2015-320933Monitor
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT
HighCVSS 7.5No exploitEPSS 10%qemu · qemuJun 15, 2015