Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Arista Networks, Inc.

First CVE: Sep 24, 2014Active for: 12 yearsTotal CVEs: 125
62.1
VTI Score
TOP TARGET

Arista Networks operates a broadly represented portfolio of network switching, routing, and security appliances that occupy critical infrastructure roles in enterprise and cloud deployments, creating a substantial attack surface across the datacenter and edge. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure concentrates in flagship products such as EOS, the NG Firewall, and the 7500 series switches. Recurring weakness classes include improper authentication, OS command injection, and improper access control—flaws typical of complex network operating systems that expose command interfaces and privilege-boundary logic. Defenders should track this vendor's advisories closely given the critical role its devices play in network segmentation and access control, and prioritize remediation for internet-facing or untrusted-input-adjacent deployments. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
125
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
3.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Arista Networks, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 24, 2014
11 years ago
Most Recent CVE
Jun 5, 2026
49 days ago

Self-Reporting Analysis

Of all the CVEs published by Arista Networks, Inc. as a CNA, 80.5% affect products that Arista Networks, Inc. develops as a vendor.

80.5%
19.5%
Self-reported: 70 (80.5%)
Third-party: 17 (19.5%)

Of all the CVEs published that affect products developed by Arista Networks, Inc., 56.0% are self-published by Arista Networks, Inc. as a CNA.

56.0%
44.0%
Self-published: 70 (56.0%)
Other CNAs: 55 (44.0%)

Products(323 total)

Top CVEs

Signals from CVEs in this vendor scope (125 CVEs).

125 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31431HIGH
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2017-14491CRITICAL
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Oct 4, 20179.885NOYES
CVE-2026-7473MEDIUM
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) t
Jun 5, 20265.869YESNO
CVE-2020-10188CRITICAL
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the net
Mar 6, 20209.868NONO
CVE-2017-18017CRITICAL
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a
Jan 3, 20189.860NONO
CVE-2020-9015CRITICAL
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shel
Feb 20, 20209.850NOYES
CVE-2024-27890CRITICAL
Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected. This can result in unexpected configuration being
Jun 4, 20269.640NONO
View all 125 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products125 CVEs
40%
39%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (10.4%)
Network91 (72.8%)
Unknown4 (3.2%)
Physical0 (0.0%)
Adjacent Network17 (13.6%)
Attack Complexity
Low106 (84.8%)
High15 (12.0%)
Unknown4 (3.2%)
User Interaction
None110 (88.0%)
Unknown4 (3.2%)
Required11 (8.8%)
Privileges Required
Low41 (32.8%)
High11 (8.8%)
None69 (55.2%)
Unknown4 (3.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (125 CVEs).

CISA KEV
4 CVEs
3.2% of CVEs· 99th percentile
Metasploit
3 CVEs
2.4% of CVEs· 97th percentile
Nuclei
2 CVEs
1.6% of CVEs· 95th percentile
ExploitDB
5 CVEs
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Arista Networks, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Arista Networks, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Arista Networks, Inc.'s Products

View all 7 CNAs →

Top CWEs