Записи arista
105 опубликованных записей вендора arista.
Профиль для исследователя
- Попали в KEV
- 6 · 5,7 %
- С эксплойтом
- 7 · 6,7 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 28,6 %
- Медиана: публикация → KEV
- 7 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')8
- CWE-284 Improper Access Control6
- CWE-287 Improper Authentication6
- CWE-20 Improper Input Validation4
- CWE-255 Credentials Management Errors4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
105 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
70На этой неделе | CVE-2026-16812Готовый эксплойт | VeloCloud Orchestrator OS Command Injectionarista · velocloud orchestrator · CWE-78 | Критическая10,0 | KEV | 1,0 % | 27 июл. 2026 г. |
68На этой неделе | CVE-2026-93952Готовый эксплойт | Security Advisory 0183arista · velocloud orchestrator · CWE-20 | Критическая9,5 | KEV | 1,1 % | 22 сент. 2026 г. |
64На этой неделе | CVE-2017-14491Proof of concept | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Критическая9,8 | — | 84,9 % | 3 окт. 2017 г. |
62На этой неделе | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Высокая8,1 | — | 99,5 % | 1 июл. 2024 г. |
62На этой неделе | CVE-2026-31431Готовый эксплойт | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | Высокая7,8 | KEV | 3,4 % | 22 апр. 2026 г. |
61На этой неделе | CVE-2020-10188Эксплойта нет | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Критическая9,8 | — | 74,3 % | 6 мар. 2020 г. |
57В плане | CVE-2026-7473Готовый эксплойт | Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypassarista · eos · CWE-1023 | Средняя6,9 | KEV | 0,6 % | 5 июн. 2026 г. |
55В плане | CVE-2017-18017Эксплойта нет | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Критическая9,8 | — | 52,8 % | 3 янв. 2018 г. |
44В плане | CVE-2020-9015Готовый эксплойт | Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow aarista · dcs-7050qx-32s-r firmware | Критическая9,8 | — | 16,5 % | 20 февр. 2020 г. |
41В плане | CVE-2015-5165Эксплойта нет | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers toxen · xen · CWE-908 | Критическая9,3 | — | 13,3 % | 12 авг. 2015 г. |
41В плане | CVE-2015-8236Эксплойта нет | Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attaarista · eos · CWE-264 | Критическая10,0 | — | 4,2 % | 19 нояб. 2015 г. |
39Наблюдать | CVE-2021-28495Эксплойта нет | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatarista · metamako operating system · CWE-287 | Критическая9,8 | — | 0,9 % | 9 сент. 2021 г. |
39Наблюдать | CVE-2021-28503Эксплойта нет | In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote atarista · eos · CWE-305 | Критическая9,8 | — | 0,7 % | 4 февр. 2022 г. |
39Наблюдать | CVE-2024-9132Эксплойта нет | The administrator is able to configure an insecure captive portal scriptarista · ng firewall · CWE-94 | Критическая9,8 | — | 0,7 % | 10 янв. 2025 г. |
38Наблюдать | CVE-2024-27889Эксплойта нет | Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).arista · ng firewall · CWE-89 | Высокая8,8 | — | 8,8 % | 4 мар. 2024 г. |
38Наблюдать | CVE-2025-2767Эксплойта нет | Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerabilityarista · ng firewall · CWE-79 | Критическая9,6 | — | 0,6 % | 23 апр. 2025 г. |
36Наблюдать | CVE-2021-28506Эксплойта нет | An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a faarista · eos · CWE-285 | Критическая9,1 | — | 1,4 % | 14 янв. 2022 г. |
35Наблюдать | CVE-2016-9012Эксплойта нет | CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via thearista · cloudvision portal · CWE-264 | Высокая8,8 | — | 1,5 % | 23 янв. 2017 г. |
35Наблюдать | CVE-2024-12829Эксплойта нет | Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerabilityarista · ng firewall · CWE-78 | Высокая8,8 | — | 1,3 % | 19 дек. 2024 г. |
35Наблюдать | CVE-2020-3973Эксплойта нет | The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.arista · velocloud orchestrator · CWE-89 | Высокая8,8 | — | 1,1 % | 8 июл. 2020 г. |
35Наблюдать | CVE-2021-28494Эксплойта нет | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication iarista · metamako operating system · CWE-287 | Высокая8,8 | — | 0,9 % | 9 сент. 2021 г. |
35Наблюдать | CVE-2024-9188Эксплойта нет | Specially constructed queries cause cross platform scripting leaking administrator tokensarista · ng firewall · CWE-79 | Высокая8,8 | — | 0,5 % | 10 янв. 2025 г. |
33Наблюдать | CVE-2015-3209Эксплойта нет | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATqemu · qemu · CWE-787 | Высокая7,5 | — | 9,7 % | 15 июн. 2015 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2026-1681270На этой неделе
VeloCloud Orchestrator OS Command Injection
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 1 %arista · velocloud orchestrator27 июл. 2026 г.
- CVE-2026-9395268На этой неделе
Security Advisory 0183
КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 1 %arista · velocloud orchestrator22 сент. 2026 г.
- CVE-2017-1449164На этой неделе
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
КритическаяCVSS 9,8Proof of conceptEPSS 85 %thekelleys · dnsmasq3 окт. 2017 г.
- CVE-2024-638762На этой неделе
Openssh: regresshion - race condition in ssh allows rce/dos
ВысокаяCVSS 8,1Proof of conceptEPSS 100 %sonicwall · sma 6200 firmware1 июл. 2024 г.
- CVE-2026-3143162На этой неделе
crypto: algif_aead - Revert to operating out-of-place
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %linux · linux kernel22 апр. 2026 г.
- CVE-2020-1018861На этой неделе
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 74 %netkit telnet project · netkit telnet6 мар. 2020 г.
- CVE-2026-747357В плане
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %arista · eos5 июн. 2026 г.
- CVE-2017-1801755В плане
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 53 %linux · linux kernel3 янв. 2018 г.
- CVE-2020-901544В плане
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow a
КритическаяCVSS 9,8Готовый эксплойтEPSS 16 %arista · dcs-7050qx-32s-r firmware20 февр. 2020 г.
- CVE-2015-516541В плане
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to
КритическаяCVSS 9,3Эксплойта нетEPSS 13 %xen · xen12 авг. 2015 г.
- CVE-2015-823641В плане
Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote atta
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %arista · eos19 нояб. 2015 г.
- CVE-2021-2849539Наблюдать
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticat
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arista · metamako operating system9 сент. 2021 г.
- CVE-2021-2850339Наблюдать
In Arista's EOS software affected releases, eAPI might skip re-evaluating user credentials when certificate based authentication is used, which allows remote at
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arista · eos4 февр. 2022 г.
- CVE-2024-913239Наблюдать
The administrator is able to configure an insecure captive portal script
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arista · ng firewall10 янв. 2025 г.
- CVE-2024-2788938Наблюдать
Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW).
ВысокаяCVSS 8,8Эксплойта нетEPSS 9 %arista · ng firewall4 мар. 2024 г.
- CVE-2025-276738Наблюдать
Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %arista · ng firewall23 апр. 2025 г.
- CVE-2021-2850636Наблюдать
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a fa
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %arista · eos14 янв. 2022 г.
- CVE-2016-901235Наблюдать
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %arista · cloudvision portal23 янв. 2017 г.
- CVE-2024-1282935Наблюдать
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %arista · ng firewall19 дек. 2024 г.
- CVE-2020-397335Наблюдать
The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %arista · velocloud orchestrator8 июл. 2020 г.
- CVE-2021-2849435Наблюдать
In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication i
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %arista · metamako operating system9 сент. 2021 г.
- CVE-2024-918835Наблюдать
Specially constructed queries cause cross platform scripting leaking administrator tokens
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %arista · ng firewall10 янв. 2025 г.
- CVE-2015-320933Наблюдать
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTAT
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %qemu · qemu15 июн. 2015 г.