Show filters
101 Total Results
Displaying 1-10 of 101
Sort by:
Attacker Value
Unknown
CVE-2020-24587
Disclosure Date: May 11, 2021 (last updated February 22, 2025)
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.
3
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated March 14, 2025)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Unknown
CVE-2023-24510
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart.
1
Attacker Value
Unknown
CVE-2023-24545
Disclosure Date: April 11, 2023 (last updated February 24, 2025)
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
1
Attacker Value
Unknown
CVE-2024-9135
Disclosure Date: March 04, 2025 (last updated March 05, 2025)
On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak memory. This may result in BGP routing processing being terminated and route flapping.
0
Attacker Value
Unknown
CVE-2024-8000
Disclosure Date: March 04, 2025 (last updated March 05, 2025)
On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is received from the AAA server resulting in only the first line of the ACL being installed after an Accelerated Software Upgrade (ASU) restart.
Note: supplicants with pending captive-portal authentication during ASU would be impacted with this bug.
0
Attacker Value
Unknown
CVE-2025-1260
Disclosure Date: March 04, 2025 (last updated March 05, 2025)
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in unexpected configuration/operations being applied to the switch.
0
Attacker Value
Unknown
CVE-2025-1259
Disclosure Date: March 04, 2025 (last updated March 05, 2025)
On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been rejected. This issue can result in users retrieving data that should not have been available
0
Attacker Value
Unknown
CVE-2024-9188
Disclosure Date: January 10, 2025 (last updated January 11, 2025)
Specially constructed queries cause cross platform scripting leaking administrator tokens
0
Attacker Value
Unknown
CVE-2024-9134
Disclosure Date: January 10, 2025 (last updated February 27, 2025)
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
0