Known vulnerabilities in Arista Extensible Operating System (EOS)

Software CPE: cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*
Total vulnerabilities: 64
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Arista Extensible Operating System (EOS) Arista Extensible Operating System (EOS) is affected by 64 known vulnerabilities: 4 high, 42 medium, 18 low Critical High Medium Low

Vulnerabilities (64)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144260 - Resource exhaustion
CWE-400 Medium
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.2F 19.08.2026 SB2026081946
SB2026082143
SB2026082144
and 1 more
#VU135099 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-12546
CWE-288 Low
No
No
4.32.11M, 4.33.8M, 4.34.6M, 4.35.4M, 4.36.1F 24.06.2026 SB2026062433
#VU135093 - Cleartext Storage of Sensitive Information
CVE-2026-11704
CWE-312 Low
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU135094 - Execution with Unnecessary Privileges
CVE-2026-11705
CWE-250 Medium
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU135095 - Incorrect Default Permissions
CVE-2026-52895
CWE-276 Low
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU135096 - Improper Certificate Validation
CVE-2026-52896
CWE-295 Medium
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU135097 - Improper Privilege Management
CVE-2026-52897
CWE-269 Low
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU135098 - Exposure of resource to wrong sphere
CVE-2026-52898
CWE-668 Low
No
No
4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F 24.06.2026 SB2026062432
#VU134147 - Incomplete Comparison with Missing Factors
CVE-2026-7473
CWE-1023 High
No
Exploited
- 09.06.2026 SB2026060970
#VU126174 - Buffer Access with Incorrect Length Value
CVE-2025-7048
CWE-805 Medium
No
No
4.31.10M, 4.32.8M, 4.33.6M, 4.34.4M, 4.35.0F 15.04.2026 SB20260415108
#VU126173 - Resource exhaustion
CVE-2025-8872
CWE-400 Medium
No
No
4.31.9M, 4.32.8M, 4.33.5M, 4.34.2F 15.04.2026 SB20260415107
#VU126171 - Improper Validation of Syntactic Correctness of Input
CVE-2025-8873
CWE-1286 Medium
No
No
4.32.7M, 4.33.5M 15.04.2026 SB20260415106
#VU126170 - Operation on a Resource after Expiration or Release
CVE-2026-2379
CWE-672 Medium
No
No
4.31.10M, 4.32.8M, 4.33.6M, 4.34.4M, 4.35.0F 15.04.2026 SB20260415105
#VU126167 - Improper Privilege Management
CVE-2025-5088
CWE-269 Medium
No
No
4.31.9M, 4.32.7M, 4.33.5M, 4.34.2F 15.04.2026 SB20260415103
#VU126168 - Improper input validation
CVE-2025-5089
CWE-20 Medium
No
No
4.31.9M, 4.32.7M, 4.33.5M, 4.34.2F 15.04.2026 SB20260415103
#VU126169 - Improper input validation
CVE-2025-5090
CWE-20 Medium
No
No
4.32.7M, 4.33.5M, 4.34.2F 15.04.2026 SB20260415103
#VU118106 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52565
CWE-61 Low
No
No
4.32.9M, 4.34.5M, 4.35.3F 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 38 more
#VU118105 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52881
CWE-61 Low
No
No
4.32.9M, 4.34.5M, 4.35.3F 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 62 more
#VU118104 - UNIX Symbolic Link (Symlink) Following
CVE-2025-31133
CWE-61 Low
Available
No
4.32.9M, 4.34.5M, 4.35.3F 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 34 more
#VU113162 - Information Exposure Through Log Files
CVE-2025-3456
CWE-532 Low
No
No
4.31.8M, 4.32.6M, 4.33.4M, 4.34.1F 22.07.2025 SB2025072258


Showing elements 1 - 20 out of 64