Arista Networks EOS
42 known vulnerabilities in Arista Networks EOS, 5 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-7473 CVSS 6.9 medium · actively exploited Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Latest vulnerabilities
- CVE-2026-73462 CVSS 7.1 high On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all…
- CVE-2026-73457 CVSS 6.0 medium Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the…
- CVE-2026-73456 CVSS 9.2 critical Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an…
- CVE-2026-73443 CVSS 5.3 medium On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2…
- CVE-2026-73442 CVSS 2.1 low On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the…
- CVE-2026-77190 CVSS 6.0 medium On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a…
- CVE-2026-73469 CVSS 6.9 medium When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be…
- CVE-2026-73468 CVSS 7.1 high A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in…
- CVE-2026-73455 CVSS 8.9 high On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause…
- CVE-2026-73453 CVSS 9.5 critical An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution…
- CVE-2026-73440 CVSS 2.3 low On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user…
- CVE-2026-73438 CVSS 7.0 high On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the…
- CVE-2026-73436 CVSS 6.0 medium On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an…
- CVE-2026-73435 CVSS 7.0 high On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet…
- CVE-2026-19640 CVSS 2.3 low On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interface) may receive…
- CVE-2026-73464 CVSS 8.7 high On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a…
- CVE-2026-73463 CVSS 6.0 medium On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition…
- CVE-2026-73461 CVSS 9.4 critical On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig…
- CVE-2026-73454 CVSS 8.6 high On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request…
- CVE-2026-73445 CVSS 6.9 medium On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect…
- CVE-2026-73439 CVSS 7.7 high On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNSI Pathz is…
- CVE-2026-2380 CVSS 5.1 medium On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and…
- CVE-2026-73447 CVSS 9.4 critical A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise…
- CVE-2026-73450 CVSS 7.0 high On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual…
- CVE-2026-73460 CVSS 7.0 high On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS…
- CVE-2026-73459 CVSS 7.0 high On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP…
- CVE-2026-73446 CVSS 7.0 high On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted…
- CVE-2026-73444 CVSS 5.3 medium On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated…
- CVE-2026-73437 CVSS 6.5 medium On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker…
- CVE-2026-19655 CVSS 7.1 high On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information…