Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/arista-networks/eos

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.

Join the discussion

A vulnerability in Arista Networks EOS with IPsec configured allows a specially crafted packet to cause the dataplane to stop processing all IPsec traffic. The control plane may detect this and attempt a reset, but traffic may not resume. Non-IPsec traffic and IPsec traffic not originating or terminating on the system are unaffected. This issue affects specific EOS versions and was reported by a customer.

Join the discussion

CVE-2024-27892 is a high-severity vulnerability in Arista Networks EOS affecting versions 4.24.0 through 4.31.0. It involves missing authentication for a critical function where a gNMI Set request can be executed despite it being expected to be rejected. This flaw can lead to unexpected configuration changes on the affected switches.

Join the discussion

CVE-2024-27890 is a vulnerability in Arista Networks EOS affecting versions 4.24.0 through 4.29.0 where a gNMI Set request can be executed without proper authentication when OpenConfig is configured. This allows unauthorized configuration changes on the switch. The vulnerability is rated high severity with a CVSS 4.0 score of 7.2. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

CVE-2024-27891 is a medium severity vulnerability in Arista Networks EOS where ACL policies may not be enforced on egressing packets if MACsec and egress ACLs are configured on the same interfaces. This improper access control can cause packets to be incorrectly allowed or denied when leaving the affected ports.

Join the discussion

CVE-2024-6858 is a medium severity vulnerability in Arista Networks EOS affecting versions 4.28.10, 4.29.0, 4.30.0, and 4.31.0. When operating in 802.1X mode, multi-authentication unauthenticated hosts might gain access to a switch port if an EAPOL capable device exists in the fallback VLAN. This improper validation of input type could lead to unauthorized network access. No official patch or remediation guidance has been provided yet.

Join the discussion
0

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

Join the discussion

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue was discovered internally by Arista and is not aware of any malicious uses of this issue in customer networks.

Join the discussion
0

On affected platforms running Arista EOS, certain serial console input might result in an unexpected reload of the device.153

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/arista-networks/eos
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses