Arista Networks, Inc.

First CVE: Sep 9, 2021Active for: 5 years
87
CVEs Published
More CVEs Published than 68% of tracked CNAs
14.5
Avg CVEs / Year
More Avg CVEs / Year than 61% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked CNAs
1.1%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Arista Networks, Inc. as a CNA, 80.5% affect products that Arista Networks, Inc. develops as a vendor.

80.5%
19.5%
Self-reported: 70Third-party: 17

Of all the CVEs published that affect products developed by Arista Networks, Inc., 56.0% are self-published by Arista Networks, Inc. as a CNA.

56.0%
44.0%
Self-published: 70Published by other CNAs: 55

Trends Over Time

The number and severity of CVEs published by Arista Networks, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2021
4 years ago
Most Recent CVE
Jun 5, 2026
49 days ago

Top CVEs

All CVEs published by Arista Networks, Inc. as a CNA, regardless of affected vendor or product.

87 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) t
Jun 5, 20265.869YESNO
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being
Jun 4, 20269.640NONO
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being
Jun 4, 20269.638NONO
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administ
Jun 5, 20266.033NONO
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW).
Jun 5, 20266.033NONO
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to t
Jun 5, 20268.332NONO
Diagnostics command injection vulnerability
Oct 23, 20257.232NONO
An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticat
Jun 5, 20266.031NONO
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detec
Jun 4, 20267.531NONO
On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. T
May 8, 202510.031NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA87 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local13 (14.9%)
Network66 (75.9%)
Unknown0 (0.0%)
Physical2 (2.3%)
Adjacent Network6 (6.9%)
Attack Complexity
Low79 (90.8%)
High8 (9.2%)
Unknown0 (0.0%)
User Interaction
None79 (90.8%)
Unknown0 (0.0%)
Required8 (9.2%)
Privileges Required
Low37 (42.5%)
High13 (14.9%)
None37 (42.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (87 CVEs).

CISA KEV
1 CVE
1.1% of CVEs· 88th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Arista Networks, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Arista Networks, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs