Arista Networks operates a broadly represented portfolio of network switching, routing, and security appliances that occupy critical infrastructure roles in enterprise and cloud deployments, creating a substantial attack surface across the datacenter and edge. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure concentrates in flagship products such as EOS, the NG Firewall, and the 7500 series switches. Recurring weakness classes include improper authentication, OS command injection, and improper access control—flaws typical of complex network operating systems that expose command interfaces and privilege-boundary logic. Defenders should track this vendor's advisories closely given the critical role its devices play in network segmentation and access control, and prioritize remediation for internet-facing or untrusted-input-adjacent deployments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arista Networks, Inc. over time
Of all the CVEs published by Arista Networks, Inc. as a CNA, 80.5% affect products that Arista Networks, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Arista Networks, Inc., 56.0% are self-published by Arista Networks, Inc. as a CNA.
Signals from CVEs in this vendor scope (125 CVEs).
125 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2017-14491CRITICAL Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | Oct 4, 2017 | 9.8 | 85 | NO | YES |
CVE-2026-7473MEDIUM On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) t | Jun 5, 2026 | 5.8 | 69 | YES | NO |
CVE-2020-10188CRITICAL utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the net | Mar 6, 2020 | 9.8 | 68 | NO | NO |
CVE-2017-18017CRITICAL The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a | Jan 3, 2018 | 9.8 | 60 | NO | NO |
CVE-2020-9015CRITICAL Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shel | Feb 20, 2020 | 9.8 | 50 | NO | YES |
CVE-2024-27890CRITICAL Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being | Jun 4, 2026 | 9.6 | 40 | NO | NO |
Signals from CVEs in this vendor scope (125 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arista Networks, Inc..
Media articles that mention a CVE ID that affects a product developed by Arista Networks, Inc. — matched by CVE ID, not by vendor name.