<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/custom_data/rss_style/rss.xsl"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
  <channel>
    <title>Arista Networks :: Security Advisories</title>
		<description><![CDATA[Arista Networks :: Security Advisories]]></description>
		<link>https://www.arista.com/en/support/advisories-notices/security-advisory</link>
		<lastBuildDate>Wed, 24 Jun 2026 08:32:05 +0000</lastBuildDate>
		<atom:link rel="self" type="application/rss+xml" href="https://www.arista.com/en/support/advisories-notices/security-advisory-rss"/>
		<language>en-gb</language>
		<copyright>© 2026 Arista Networks, Inc. All rights reserved.</copyright>
		<managingEditor>webadmin@arista.com (Web Admin)</managingEditor>
		<item>
			<title>Security Advisory 0143</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24112-security-advisory-0143</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24112-security-advisory-0143</guid>
			<description><![CDATA[
Date: June 23, 2026



Revision
Date
Changes


1.0
Jun 23, 2026
Initial release



Description
All of the CVEs covered in this advisory apply to affected platforms running Arista EOS with the Streaming Telemetry Agent (aka TerminAttr) enabled. This issue primarily affects customers using the Streaming Telemetry Agent to connect to CloudVision or a gNMI server.
All of these issues were discovered internally by Arista and Arista is not aware of any malicious uses of these issues ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Tue, 23 Jun 2026 00:37:30 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0142</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24111-security-advisory-0142</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24111-security-advisory-0142</guid>
			<description><![CDATA[
Date: June 23, 2026



Revision
Date
Changes


1.0
June 23, 2026
Initial release



The CVE-ID tracking this issue: CVE-2026-12546 CVSSv3.1 Base Score: 6.0 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L)CVSSv4.0 Base Score: 5.1 (CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:L/SI:L/SA:L) Common Weakness Enumeration: CWE-288: Authentication Bypass Using an Alternate Path or Channel This vulnerability is being tracked by BUG1359868
Description
On affected platforms running A ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Tue, 23 Jun 2026 00:35:10 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0141</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24108-security-advisory-0141</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24108-security-advisory-0141</guid>
			<description><![CDATA[
Date: June 16, 2026
 
 



Revision
Date
Changes


1.0
June 16, 2026
Initial release



CVSSv3.1 Base Score: 8.2 (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N) CVSSv4.0 Base Score: 5.3 (CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N) Common Weakness Enumeration: CWE-653 (Insufficient Compartmentalization)
 
This vulnerability is being tracked by BUG 1787021
Description
The purpose of this advisory is to provide an announcement regarding potential vulnerabi ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Mon, 15 Jun 2026 21:20:27 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0140</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24074-security-advisory-0140</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24074-security-advisory-0140</guid>
			<description><![CDATA[
Date: June 3, 2026



Revision
Date
Changes


1.0
June 3, 2026
Initial release



 
 
The CVE-ID tracking this issue: CVE-2026-10040 CVSSv3.1 Base Score: 6.0 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H) CVSSv4.0 Base Score: 6.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N) Common Weakness Enumeration: CWE-348: Use of Less Trusted Source This vulnerability is being tracked by BUG1315802
Description
A user with local eos-admin privileges on affected Arist ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Mon, 01 Jun 2026 23:27:32 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0139</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24029-security-advisory-0139</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24029-security-advisory-0139</guid>
			<description><![CDATA[
Date: May 19, 2026



Revision
Date
Changes


1.0
May 19, 2026
Initial release



The CVE-ID tracking this issue: CVE-2025-49844 CVSSv3.1 Base Score: 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) CVSSv4.0 Base Score: 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) Common Weakness Enumeration: CWE-416 Use After FreeThis vulnerability is being tracked by BUG1140119 and BUG1391625
Description
On affected Arista platforms running Media Control Service (M ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Mon, 18 May 2026 22:50:28 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0138</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24019-security-advisory-0138</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24019-security-advisory-0138</guid>
			<description><![CDATA[
Date: May 8, 2026
 



Revision
Date
Changes


1.0
May 8, 2026
Initial release


1.1
May 18, 2026
Updated affected products and added mitigation section



 
The CVE-ID’s tracking this issue: CVE-2026-43284, and CVE-2026-43500.
Description
Arista Networks is providing this security update in response to a recent, publicly disclosed security vulnerability widely known as “Dirty Frag”. Exploitation of this issue allows for an unprivileged local user to gain root access to ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Fri, 08 May 2026 22:22:55 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0137</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24005-security-advisory-0137</guid>
			<description><![CDATA[
Date: May 5, 2026



Revision
Date
Changes


1.0
May 5, 2026
Initial release


1.1
May 7, 2026
Clarified 7280R3, 7500R3 and 7800R3 exposure is limited


1.2
May 13, 2026
Updated Mitigation section with a note of caution


1.3
May 20, 2026
Updated Approach 2 - Applying ACL on Decapsulation Switches



The CVE-ID tracking this issue: CVE-2026-7473 CVSSv3.1 Base Score: 5.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N) CVSSv4.0 Base Score: 6.8 (CVSS:4.0/AV:N/AC:L/AT: ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Tue, 05 May 2026 03:41:31 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0136</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/24004-security-advisory-0136</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/24004-security-advisory-0136</guid>
			<description><![CDATA[
Date: May 1, 2026



Revision
Date
Changes


1.0
May 1, 2026
Initial release


1.1
May 7, 2026
Additional required configuration for exploitation information added


1.2
May 11, 2026
Advisory updated with additional mitigations.



The CVE-ID tracking this issue: CVE-2026-31431 CVSSv3.1 Base Score: 7.8 (CVSS:3.1/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Common Weakness Enumeration: CWE-1288: Improper Validation of Consistency within Input
This vulnerability is bei ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Sat, 02 May 2026 00:09:38 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0135</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/23784-security-advisory-0135</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/23784-security-advisory-0135</guid>
			<description><![CDATA[
 
Date: April 7, 2026
 



Revision
Date
Changes


1.0
April 7th, 2026
Initial release


1.1
April 28th, 2026
Correction to fixed releases(fixed in 4.32.10, not 4.32.9)



The CVE-ID tracking this issue: CVE-2025-31133 CVSSv3.1 Base Score: 7.8/10 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H) CVSS:4.0 Base Score: 7.3/10 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)Common Weakness Enumeration: CWE-61: UNIX Symbolic Link (Symlink) Following
The CVE-ID t ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Mon, 06 Apr 2026 18:13:39 +0000</pubDate>
		</item>
		<item>
			<title>Security Advisory 0134</title>
			<link>https://www.arista.com/en/support/advisories-notices/security-advisory/23419-security-advisory-0134</link>
			<guid isPermaLink="true">https://www.arista.com/en/support/advisories-notices/security-advisory/23419-security-advisory-0134</guid>
			<description><![CDATA[
 
Date: February 17, 2026
 



Revision
Date
Changes


1.0
February 17, 2026
Initial release



The CVE-ID tracking this issue: CVE-2026-2379 CVSSv3.1 Base Score: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)Common Weakness Enumeration: CWE-672: Operation on a Resource after Expiration or Release This vulnerability is being tracked by BUG 1188976
Description
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may ...]]></description>
			<category>Security Advisories</category>
			<pubDate>Tue, 17 Feb 2026 01:17:46 +0000</pubDate>
		</item>
	</channel>
</rss>