Arista Networks, Inc.
First CVE: Sep 9, 2021Active for: 5 years
87
CVEs Published
More CVEs Published than 68% of tracked CNAs
14.5
Avg CVEs / Year
More Avg CVEs / Year than 61% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked CNAs
1.1%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Arista Networks, Inc. as a CNA, 80.5% affect products that Arista Networks, Inc. develops as a vendor.
80.5%
19.5%
Self-reported: 70Third-party: 17
Of all the CVEs published that affect products developed by Arista Networks, Inc., 56.0% are self-published by Arista Networks, Inc. as a CNA.
56.0%
44.0%
Self-published: 70Published by other CNAs: 55
Trends Over Time
The number and severity of CVEs published by Arista Networks, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2021
4 years ago
Most Recent CVE
Jun 5, 2026
49 days ago
Top CVEs
All CVEs published by Arista Networks, Inc. as a CNA, regardless of affected vendor or product.
87 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7473MEDIUM On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) t | Jun 5, 2026 | 5.8 | 69 | YES | NO |
CVE-2024-27890CRITICAL Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being | Jun 4, 2026 | 9.6 | 40 | NO | NO |
CVE-2024-27892CRITICAL Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being | Jun 4, 2026 | 9.6 | 38 | NO | NO |
CVE-2026-25622MEDIUM A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administ | Jun 5, 2026 | 6.0 | 33 | NO | NO |
CVE-2026-25620MEDIUM An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). | Jun 5, 2026 | 6.0 | 33 | NO | NO |
CVE-2025-5088HIGH An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to t | Jun 5, 2026 | 8.3 | 32 | NO | NO |
CVE-2025-6978HIGH Diagnostics command injection vulnerability | Oct 23, 2025 | 7.2 | 32 | NO | NO |
CVE-2026-25623MEDIUM An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticat | Jun 5, 2026 | 6.0 | 31 | NO | NO |
CVE-2025-8873HIGH On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detec | Jun 4, 2026 | 7.5 | 31 | NO | NO |
CVE-2024-11186CRITICAL On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. T | May 8, 2025 | 10.0 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA87 CVEs
44%
41%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (14.9%)
Network66 (75.9%)
Unknown0 (0.0%)
Physical2 (2.3%)
Adjacent Network6 (6.9%)
Attack Complexity
Low79 (90.8%)
High8 (9.2%)
Unknown0 (0.0%)
User Interaction
None79 (90.8%)
Unknown0 (0.0%)
Required8 (9.2%)
Privileges Required
Low37 (42.5%)
High13 (14.9%)
None37 (42.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (87 CVEs).
CISA KEV
1 CVE
1.1% of CVEs· 88th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Arista Networks, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Arista Networks, Inc. as a CNA — matched by CVE ID, not by organization name.