Show filters
97 Total Results
Displaying 81-90 of 97
Sort by:
Attacker Value
Unknown

CVE-2019-14810

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under race conditions, the LDP agent can establish an LDP session with a malicious peer potentially allowing the possibility of a Denial of Service (DoS) attack on route updates and in turn potentially leading to an Out of Memory (OOM) condition that is disruptive to traffic forwarding. Affected EOS versions include: 4.22 release train: 4.22.1F and earlier releases 4.21 release train: 4.21.0F - 4.21.2.3F, 4.21.3F - 4.21.7.1M 4.20 release train: 4.20.14M and earlier releases 4.19 release train: 4.19.12M and earlier releases End of support release trains (4.18 and 4.17)
Attacker Value
Unknown

CVE-2018-14008

Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
0
Attacker Value
Unknown

CVE-2018-12357

Disclosure Date: August 15, 2019 (last updated November 27, 2024)
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
0
Attacker Value
Unknown

CVE-2019-18615

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.
Attacker Value
Unknown

CVE-2019-18181

Disclosure Date: May 16, 2019 (last updated November 27, 2024)
In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass permissions for restricted functionality via CVP API calls through the Configlet Builder modules. This vulnerability can potentially enable authenticated users with read-only access to take actions that are otherwise restricted in the GUI.
Attacker Value
Unknown

CVE-2018-5254

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
Arista EOS before 4.20.2F allows remote BGP peers to cause a denial of service (Rib agent restart) via a malformed path attribute in an UPDATE message.
0
Attacker Value
Unknown

CVE-2018-5255

Disclosure Date: March 05, 2018 (last updated November 26, 2024)
The Mlag agent in Arista EOS 4.19 before 4.19.4M and 4.20 before 4.20.2F allows remote attackers to cause a denial of service (agent restart) via crafted UDP packets.
0
Attacker Value
Unknown

CVE-2017-18017

Disclosure Date: January 03, 2018 (last updated April 25, 2024)
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
Attacker Value
Unknown

CVE-2017-14491

Disclosure Date: October 04, 2017 (last updated January 15, 2025)
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
Attacker Value
Unknown

CVE-2016-9012

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.
0