Arista Eos
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Arista Eos.
By the Year
In 2026 there have been 29 vulnerabilities in Arista Eos with an average score of 5.7 out of ten. Last year, in 2025 Eos had 10 security vulnerabilities published. That is, 19 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.80
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 29 | 5.70 |
| 2025 | 10 | 6.50 |
| 2024 | 0 | 0.00 |
| 2023 | 3 | 7.60 |
| 2022 | 4 | 8.45 |
| 2021 | 4 | 6.50 |
| 2020 | 8 | 6.75 |
| 2019 | 2 | 0.00 |
| 2018 | 3 | 7.00 |
It may take a day or so for new Eos vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Arista Eos Security Vulnerabilities
Arista EOS IGMP Snooping Crash CVE-2026-73462
CVE-2026-73462
6.5 - Medium
- September 16, 2026
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.
Out-of-bounds Read
Clear-text gNPSI Client Credentials Logged on Arista EOS
CVE-2026-73457
5.3 - Medium
- September 16, 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.
Insertion of Sensitive Information into Log File
Arista EOS gRPC gNPSI Remote Code Execution via Unauth Client
CVE-2026-73456
10 - Critical
- September 16, 2026
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Code Injection
Arista EOS VRRP Auth Credentials Logged in Cleartext
CVE-2026-73442
3 - Low
- September 16, 2026
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
Insertion of Sensitive Information into Log File
Arista EOS PIMSM Agent DoS 4.34-4.36
CVE-2026-77190
6.5 - Medium
- September 16, 2026
On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service.
Improper Input Validation
Arista EOS Multicast Forwarding State Premature Expiry (<=4.36.1F)
CVE-2026-73468
6.5 - Medium
- September 16, 2026
A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
Always-Incorrect Control Flow Implementation
Arista EOS SNMPv3 Credential Exposure via Hashed Key in Config
CVE-2026-73440
4.2 - Medium
- September 16, 2026
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who gains access to this sensitive information could leverage it to perform unauthorized read operations on SNMP tables or to send fraudulent trap notifications to the Network Management System (NMS). This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Improper Removal of Sensitive Information Before Storage or Transfer
Arista EOS 4.35.0F-4.35.4M Loose uRPF Lacks Drop on 7050X4/7358X4
CVE-2026-73469
5.8 - Medium
- September 16, 2026
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
AuthZ
Arista EOS P4Runtime unauth RCE via crafted packet injection
CVE-2026-73453
10 - Critical
- September 16, 2026
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled by default in Arista EOS. By crafting a malicious packet during the initiation of a P4Runtime session, an attacker can obtain complete administrative control over the compromised switch. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Code Injection
Arista EOS OSPFv3 Agent Restart Vulnerability (Before 4.36.0.1F)
CVE-2026-73455
7.5 - High
- September 16, 2026
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
length manipulation
Arista EOS OSPFv3 Agent Restart via Unauth Packet Crash
CVE-2026-73438
5.3 - Medium
- September 16, 2026
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpectedly. The crash results in the loss of all OSPFv3 adjacencies on the affected device and may disrupt routing across the broader OSPF domain until the agent recovers. This issue was reported externally by Dravanet Inc., and Arista is not aware of any malicious exploitation of this vulnerability in customer networks.
assertion failure
Arista EOS OSPFv2 Packet Causing OSPF Restart (CVE-2026-73436)
CVE-2026-73436
6.5 - Medium
- September 16, 2026
On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Improper Validation of Specified Quantity in Input
Arista EOS gNMI Authorization Bypass Allowing Privilege Escalation
CVE-2026-19640
4.2 - Medium
- September 16, 2026
On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive incorrect authorization results, potentially allowing access beyond their currently assigned permissions. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
AuthZ
Arista EOS MLAG Dual Primary State ErrDisable via Unauth Packets (v4.334.36)
CVE-2026-73450
6.9 - Medium
- September 16, 2026
On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.
Insufficient Verification of Data Authenticity
Premature IS-IS Graceful Restart Termination in Arista EOS <4.36.1F
CVE-2026-73460
6.1 - Medium
- September 15, 2026
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
AuthZ
Arista EOS 4.36.0-4.36.1F IS-IS LSP PDU Injection Causes LSP Purge
CVE-2026-73459
7.4 - High
- September 15, 2026
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.
Improper Validation of Integrity Check Value
Arista EOS 4.31-4.36: IS-IS Adjacency Tear-Down via Crafted Hello PDU
CVE-2026-73446
7.4 - High
- September 15, 2026
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Incorrect Behavior Order
Arista EOS VRRPv2 IP-AH Auth Bypass Enables Master Role Takeover
CVE-2026-73444
4.7 - Medium
- September 15, 2026
On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.
Incorrect Implementation of Authentication Algorithm
EOS 4.x Race Condition Leaves Supplicant Authorized After Clear Dot1X Host-All
CVE-2026-75945
2.6 - Low
- September 14, 2026
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
Insufficient Cleanup
Race Cond. in EOS 4.36.x ACL Agent Leaves Stale Entry (CVE-2026-75944)
CVE-2026-75944
2.6 - Low
- September 14, 2026
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an AclAgent restart by an administrator) is required for the unintended behavior to take effect.
Insufficient Cleanup
Arista EOS Traffic Leakage on Supplicant Removal (4.36.0)
CVE-2026-75943
2.6 - Low
- September 14, 2026
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.
Insufficient Cleanup
Arista EOS 4.35.0 ACL Bypass via Authenticated Supplicant Window
CVE-2026-77191
2.6 - Low
- September 14, 2026
An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.
AuthZ
Arista EOS 4.34-4.36 RADIUS Proxy Dynamic Auth Bypass
CVE-2026-73449
5.9 - Medium
- September 14, 2026
On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can prevent RADIUS dynamic authorization messages, including Change-of-Authorization (CoA) and Disconnect-Requests as defined in RFC 5176, from being applied to locally authenticated 802.1X sessions. This allows an endpoint session that a RADIUS server or network access control system has ordered disconnected to remain authorized on the network. Both 802.1X port authentication with dynamic authorization and RADIUS proxy with dynamic authorization must be explicitly configured for a deployment to be exposed to this issue. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Authentication Bypass by Spoofing
Arista EOS <4.36: VXLAN/GRE Decap Misidentification Leads to Tunnel Spoofing
CVE-2026-7473
5.8 - Medium
- June 05, 2026
On affected platforms running Arista EOS where a tunnel decapsulation configurationsuch as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interfaceis present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not verify the tunnel protocol type, potentially leading to the unexpected processing of non-configured tunnel traffic. This issue has been reported as being exploited in the wild.
Incomplete Comparison with Missing Factors
Arista EOS IPsec DP DoS 4.33.x and 4.32.x series
CVE-2025-8873
7.5 - High
- June 04, 2026
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.
Improper Validation of Syntactic Correctness of Input
EOS 4.254.31 Auth Bypass via 802.1x on Access VLANs
CVE-2023-5502
5.9 - Medium
- June 04, 2026
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, and routing enabled on the access VLAN of the ports, a malicious supplicant may be able to bypass the requirement to perform 802.1x authentication.
authentification
Arista EOS <=4.32: ACL MACsec Egress Bypass
CVE-2024-27891
5.3 - Medium
- June 04, 2026
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports. This can cause outgoing packets to incorrectly be allowed or denied.
Authorization
Arista EOS 4.284.31: Unauth Host via EAPOL in 802.1X Mode
CVE-2024-6858
6.5 - Medium
- June 04, 2026
In Aristas EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.
Improper Validation of Specified Type of Input
Arista EOS MACsec Crash via Crafted Packet (4.34.3.1M)
CVE-2025-7048
4.3 - Medium
- January 06, 2026
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.
Buffer Access with Incorrect Length Value
Arista EOS OSPFv3 CPU Exhaustion via Crafted Packet
CVE-2025-8872
6.5 - Medium
- December 16, 2025
On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue was discovered internally by Arista and is not aware of any malicious uses of this issue in customer networks.
Resource Exhaustion
Arista EOS IPsec Anti-Replay Duplicate Packet Forgery Vulnerability
CVE-2025-2796
- May 27, 2025
On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability. Note: this issue does not affect VXLANSec or MACSec encryption functionality.
Arista EOS Traffic Policy Skip Untagged Packets – Improper Drop
CVE-2024-9448
- May 08, 2025
On affected platforms running Arista EOS with Traffic Policies configured the vulnerability will cause received untagged packets not to hit Traffic Policy rules that they are expected to hit. If the rule was to drop the packet, the packet will not be dropped and instead will be forwarded as if the rule was not in place. This could lead to packets being delivered to unexpected destinations.
Arista EOS Tunnelsec Agent Restart Exposes Packets in Clear over Secure VxLAN
CVE-2024-12378
- May 08, 2025
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
Arista EOS gNOI RPC Exposes Remote Credentials via Logging
CVE-2025-0936
- May 07, 2025
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).
Arista EOS gNOI bypass allows unauthorized config changes
CVE-2025-1260
- March 04, 2025
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
Arista EOS gNOI Request Bypass via OpenConfig
CVE-2025-1259
- March 04, 2025
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
Arista EOS VLAN Tag Misprocessing Causing Control Plane Instability
CVE-2024-5872
- January 10, 2025
On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
Arista EOS SNMP snmpd Mem Leak by Crafted Packet
CVE-2024-7095
- January 10, 2025
On affected platforms running Arista EOS with SNMP configured, if snmp-server transmit max-size is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out until snmpd is restarted) and memory pressure for other processes on the switch. Increased memory pressure can cause processes other than snmpd to be at risk for unexpected termination as well.
Arista EOS PBR/BGP Flowspec IP Options Bypass
CVE-2024-6437
- January 10, 2025
On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next hop: policy-based routing (PBR), BGP Flowspec, or interface traffic policy -- certain IP traffic such as IPv4 packets with IP options may bypass the feature's set nexthop action and be slow-path forwarded (FIB routed) by the kernel as the packets are trapped to the CPU instead of following the redirect action's destination.
Arista EOS DHCP Relay Agent Crash via Malformed DHCP Packet
CVE-2023-24510
7.5 - High
- June 05, 2023
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
Improper Handling of Exceptional Conditions
Privilege Escalation in Arista EOS Standby Supervisor via RPR/SSO
CVE-2023-24509
7.8 - High
- April 13, 2023
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.
Arista EOS PTP Agent Crash DoS from Malformed PTP TLV
CVE-2021-28510
7.5 - High
- January 26, 2023
For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invalid Type-Length-Value (TLV) causes the PTP agent to restart. Repeated restarts of the service will make the service unavailable.
Improper Validation of Specified Quantity in Input
The impact of this vulnerability is
CVE-2021-28503
9.8 - Critical
- February 04, 2022
The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate based authentication is used, which allows remote attackers to access the device via eAPI.
authentification
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA APIs by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
CVE-2021-28500
7.8 - High
- January 14, 2022
An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA APIs by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed
CVE-2021-28507
7.1 - High
- January 14, 2022
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially
CVE-2021-28506
9.1 - Critical
- January 14, 2022
An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.
Missing Authentication for Critical Function
On systems running Arista EOS and CloudEOS with the affected release version
CVE-2021-28496
6.5 - Medium
- October 21, 2021
On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the password configured for use by BiDirectional Forwarding Detection (BFD) will be leaked when displaying output over eAPI or other JSON outputs to other authenticated users on the device. The affected EOS Versions are: all releases in 4.22.x train, 4.23.9 and below releases in the 4.23.x train, 4.24.7 and below releases in the 4.24.x train, 4.25.4 and below releases in the 4.25.x train, 4.26.1 and below releases in the 4.26.x train
Insufficiently Protected Credentials
A flaw was found in dnsmasq before version 2.83
CVE-2020-25686
- January 20, 2021
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to substantially reduce the number of attempts that it would have to perform to forge a reply and have it accepted by dnsmasq. This issue is mentioned in the "Birthday Attacks" section of RFC5452. If chained with CVE-2020-25684, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.
Improperly Implemented Security Check for Standard
A flaw was found in dnsmasq before version 2.83
CVE-2020-25684
- January 20, 2021
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an attacker on the network would have to perform to forge a reply and get it accepted by dnsmasq. This issue contrasts with RFC5452, which specifies a query's attributes that all must be used to match a reply. This flaw allows an attacker to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25685 or CVE-2020-25686, the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.
Improperly Implemented Security Check for Standard
A flaw was found in dnsmasq before version 2.83
CVE-2020-25685
- January 20, 2021
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to find several different domains all having the same hash, substantially reducing the number of attempts they would have to perform to forge a reply and get it accepted by dnsmasq. This is in contrast with RFC5452, which specifies that the query name is one of the attributes of a query that must be used to match a reply. This flaw could be abused to perform a DNS Cache Poisoning attack. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.
Inadequate Encryption Strength
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Arista Eos or by Arista? Click the Watch button to subscribe.