Security Advisories

 

Arista Networks is committed to maintaining the highest standards of security across our product portfolio. Leveraging extensive testing and monitoring of vulnerabilities to isolate and neutralize threats early, Arista's Product Security Incident Response Team (PSIRT) provides global coverage for public reporting of possible security vulnerabilities across the product portfolio.

The PSIRT team monitors industry-wide vulnerability reporting as well as providing a single point of contact for customers and interested third parties to investigate and identify potential threats. The PSIRT team also works to communicate these issues back to the user community in a timely manner.

Arista's approach to vulnerability management and links to best practice guidelines can be found here.

For technical assistance with workarounds and hotfix installations recommended in security advisories, please contact the Arista Support team at このメールアドレスはスパムボットから保護されています。閲覧するにはJavaScriptを有効にする必要があります。.

Report security vulnerabilities found in Arista products to the PSIRT team via このメールアドレスはスパムボットから保護されています。閲覧するにはJavaScriptを有効にする必要があります。. It is recommended to use Arista's PGP key for secure and private communication directly with the PSIRT team.

Arista PSIRT is happy to work with researchers on discovered vulnerabilities in Arista products, the assignment of CVEs, and timelines for responsible disclosure. If a researcher discovers a new vulnerability they will be acknowledged in the advisory related to the vulnerability. Arista PSIRT is interested in receiving reports on issues affecting features in both Arista code as well as Open Source Software used in Arista products. Security issues found in Open Source Software which do not affect Arista products are out of the scope of Arista and should be referred to the appropriate CNA found here.

 

PSIRT Advisories

The following advisories and referenced materials are provided on an "as is" basis for use at your own risk. Arista Networks reserves the right to change or update the advisories without notice at any time.

Security Advisory 0152

September 9, 2026

Crafted login password can cause a session resource leak, potentially causing DoS for authentication.

Security Advisory 0151

September 9, 2026

Restarting the secondary switchcard agent can cause Security ACLs on shared SVIs to stop functioning, resulting in incorrect traffic forwarding.

Security Advisory 0150

September 9, 2026

Brief window between 802.1X authentication and policy enforcement allows a supplicant unrestricted network access.

Security Advisory 0149

September 9, 2026

RADIUS authorization messages may be misrouted, potentially granting unauthorized network access to 802.1X clients. Stale access policies may persist on a port after a transient failure

Security Advisory 0148

September 2, 2026

As part of Arista’s ongoing commitment to security and transparency, we are providing advance notice for multiple Security Advisories scheduled for publication on September 09, 2026.

Security Advisory 0147

August 25, 2026

Multiple vulnerabilities have been discovered in OpenSSH before version 10.4, which is shipped with multiple Arista products. One vulnerability (CVE-2026-60001) affects the server-side SSH daemon (sshd). The remaining three vulnerabilities (CVE-2026-60002, CVE-2026-59995, CVE-2026-59996) affect the client-side SSH, Secure File Transfer Protocol (SFTP), and Secure Copy Protocol (SCP) utilities, respectively.

Security Advisory 0146

August 19, 2026

Arista Networks is providing this security update in response to the following list of gRPC-go security vulnerabilities posted by Google. Arista products are affected solely by the HTTP/2 Rapid Reset DOS Bypass vulnerability, wherein an unauthenticated remote attacker can exploit unthrottled HTTP/2 stream reset to bypass rate-limiting controls, consuming excessive CPU resources and causing a Denial of Service (DoS). Arista products are not impacted by the xDS RBAC vulnerabilities.

Security Advisory 0145

July 27, 2026

SQL injection enabling server-side request forgery in a VeloCloud Orchestrator (VCO) flow metrics API method. An input validation vulnerability exists in an API component of the orchestrator.

Server-side request forgery due to missing input validation in a VCO feature.A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible.

Security Advisory 0144

July 27, 2026

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. 

This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out.

This issue was discovered externally and is known to be actively exploited.

Security Advisory 0143

June 23, 2026

All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with the Streaming Telemetry Agent (aka TerminAttr) enabled. This issue primarily affects customers using the Streaming Telemetry Agent to connect to CloudVision or a gNMI server.

All of these issues were discovered internally by Arista and Arista is not aware of any malicious uses of these issues in customer networks.