Known Vulnerabilities for products from Arista

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Arista".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Arista can be found at device.report : Arista

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-93952 json VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged i... Not Provided 2026-09-22 2026-09-23
CVE-2026-77190 json Not Provided 2026-09-16 2026-09-16
CVE-2026-73469 json Not Provided 2026-09-16 2026-09-16
CVE-2026-73467 json Not Provided 2026-09-15 2026-09-16
CVE-2026-73466 json Not Provided 2026-09-15 2026-09-17
CVE-2026-73465 json Not Provided 2026-09-15 2026-09-17
CVE-2026-73464 json Not Provided 2026-09-16 2026-09-17
CVE-2026-73463 json Not Provided 2026-09-16 2026-09-16
CVE-2026-73462 json Not Provided 2026-09-16 2026-09-17
CVE-2026-73460 json Not Provided 2026-09-16 2026-09-16
CVE-2026-73459 json Not Provided 2026-09-16 2026-09-16
CVE-2026-25624 json An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge T... Not Provided 2026-06-05 2026-07-23
CVE-2026-25623 json An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Managemen... Not Provided 2026-06-05 2026-07-23
CVE-2026-25622 json A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generat... Not Provided 2026-06-05 2026-07-23
CVE-2026-25621 json A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall ... Not Provided 2026-06-05 2026-07-23
CVE-2026-25620 json An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threa... Not Provided 2026-06-05 2026-07-23
CVE-2026-16812 json VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged i... Not Provided 2026-07-27 2026-07-28
CVE-2026-7473 json On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN),... Not Provided 2026-06-05 2026-06-09
CVE-2024-6387 json A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead ssh... Not Provided 2024-07-01 2026-09-01
CVE-2023-24548 json On affected platforms running Arista EOS with VXLAN configured, malformed or truncated packets received over a VXLAN tunnel a... 6.5 - MEDIUM 2023-08-29 2023-09-05

Known software with vulnerabilities from Arista

Type Vendor Product Version
HardwareArista7010t-48-
HardwareArista7020r-
HardwareArista7280e-
HardwareArista7280r-
HardwareArista7280r2-
HardwareArista7280r3-
HardwareArista7500e-
HardwareArista7500r-
HardwareArista7500r2-
HardwareArista7500r3-
ApplicationAristaCloudeos4.21.11m
ApplicationAristaCloudvision Exchange-
ApplicationAristaCloudvision Portal2015.1.1
HardwareAristaDcs-7050s-
HardwareAristaDcs-7050sx-
HardwareAristaDcs-7050t-
Operating
System
AristaEos4.15
Operating
System
AristaExtensible Operating System-
ApplicationAristaVeos4.21.11m

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report