Improper privilege management in Arista Extensible Operating System (EOS) and Arista CloudEOS VM - CVE-2025-5088
Published: April 15, 2026
Vulnerability details
The vulnerability allows a remote user to obtain full root access to all servers in the CVX cluster.
The vulnerability exists due to improper privilege management in the MCS Redis service when handling an authenticated Redis session. A remote user can use an authenticated Redis session to obtain full root access to all servers in the CVX cluster.
Only systems with the MCS service enabled are vulnerable, and Redis communication including authentication occurs over plaintext.
Affected software
Arista CloudEOS VM
How to mitigate CVE-2025-5088
Arista CloudEOS VM - addressed in versions 4.31.9M, 4.32.7M, 4.33.5M, 4.34.2F