#VU126167 Improper privilege management in Arista Extensible Operating System (EOS) and Arista CloudEOS VM - CVE-2025-5088
Published: April 15, 2026
Arista Extensible Operating System (EOS)
Arista CloudEOS VM
Arista Networks
Description
The vulnerability allows a remote user to obtain full root access to all servers in the CVX cluster.
The vulnerability exists due to improper privilege management in the MCS Redis service when handling an authenticated Redis session. A remote user can use an authenticated Redis session to obtain full root access to all servers in the CVX cluster.
Only systems with the MCS service enabled are vulnerable, and Redis communication including authentication occurs over plaintext.