Перейти к содержимому
Noroxi

Записи arista

105 опубликованных записей вендора arista.

Профиль для исследователя

Попали в KEV
6 · 5,7 %
С эксплойтом
7 · 6,7 %
Pre-auth RCE
11
С записью об исправлении
28,6 %
Медиана: публикация → KEV
7 дн.

Все записи

105 записей
  • CVE-2014-6271
    99Срочно

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2014-7169
    99Срочно

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    gnu · bash24 сент. 2014 г.

  • CVE-2026-16812
    70На этой неделе

    VeloCloud Orchestrator OS Command Injection

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %

    arista · velocloud orchestrator27 июл. 2026 г.

  • CVE-2026-93952
    68На этой неделе

    Security Advisory 0183

    КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 1 %

    arista · velocloud orchestrator22 сент. 2026 г.

  • CVE-2017-14491
    64На этой неделе

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via

    КритическаяCVSS 9,8Proof of conceptEPSS 85 %

    thekelleys · dnsmasq3 окт. 2017 г.

  • CVE-2024-6387
    62На этой неделе

    Openssh: regresshion - race condition in ssh allows rce/dos

    ВысокаяCVSS 8,1Proof of conceptEPSS 100 %

    sonicwall · sma 6200 firmware1 июл. 2024 г.

  • CVE-2026-31431
    62На этой неделе

    crypto: algif_aead - Revert to operating out-of-place

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %

    linux · linux kernel22 апр. 2026 г.

  • CVE-2020-10188
    61На этой неделе

    utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus

    КритическаяCVSS 9,8Эксплойта нетEPSS 74 %

    netkit telnet project · netkit telnet6 мар. 2020 г.

  • CVE-2026-7473
    57В плане

    Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %

    arista · eos5 июн. 2026 г.

  • CVE-2017-18017
    55В плане

    The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac

    КритическаяCVSS 9,8Эксплойта нетEPSS 53 %

    linux · linux kernel3 янв. 2018 г.

  • CVE-2020-9015
    44В плане

    Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a

    КритическаяCVSS 9,8Готовый эксплойтEPSS 16 %

    arista · dcs-7050qx-32s-r firmware20 февр. 2020 г.

  • CVE-2015-5165
    41В плане

    The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to

    КритическаяCVSS 9,3Эксплойта нетEPSS 13 %

    xen · xen12 авг. 2015 г.

  • CVE-2015-8236
    41В плане

    Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    arista · eos19 нояб. 2015 г.

  • CVE-2021-28495
    39Наблюдать

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    arista · metamako operating system9 сент. 2021 г.

  • CVE-2021-28503
    39Наблюдать

    In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    arista · eos4 февр. 2022 г.

  • CVE-2024-9132
    39Наблюдать

    The administrator is able to configure an insecure captive portal script

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    arista · ng firewall10 янв. 2025 г.

  • CVE-2024-27889
    38Наблюдать

    Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %

    arista · ng firewall4 мар. 2024 г.

  • CVE-2025-2767
    38Наблюдать

    Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    arista · ng firewall23 апр. 2025 г.

  • CVE-2021-28506
    36Наблюдать

    An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    arista · eos14 янв. 2022 г.

  • CVE-2016-9012
    35Наблюдать

    CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    arista · cloudvision portal23 янв. 2017 г.

  • CVE-2024-12829
    35Наблюдать

    Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    arista · ng firewall19 дек. 2024 г.

  • CVE-2020-3973
    35Наблюдать

    The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    arista · velocloud orchestrator8 июл. 2020 г.

  • CVE-2021-28494
    35Наблюдать

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    arista · metamako operating system9 сент. 2021 г.

  • CVE-2024-9188
    35Наблюдать

    Specially constructed queries cause cross platform scripting leaking administrator tokens

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    arista · ng firewall10 янв. 2025 г.

  • CVE-2015-3209
    33Наблюдать

    Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT

    ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %

    qemu · qemu15 июн. 2015 г.