CVE security advisories and vulnerability history for EOS by Arista Networks.
71
Total CVEs
Published
3
In CISA KEV
Exploited in the wild
10
Public exploits
PoC or exploit code
7.1
Avg CVSS
2014–2026
Last updated
Overview
Arista Networks EOS has 71 published CVE records since 2014, of which 3 are in CISA's Known Exploited Vulnerabilities catalog and 10 have a known public exploit. The average CVSS base score across scored CVEs is 7.1.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Arista Networks EOS, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list. Affected platforms include 7010 Series, 7010X Series, 7020R Series, 7020SRG Series, 7050X/X2/X3/X4 Series, 7050X3/X4.
Severity and exploitation
How the CVSS severity of Arista Networks EOS's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical12
High28
Medium25
Low6
In CISA’s Known Exploited Vulnerabilities catalog
3
3 of Arista Networks EOS's CVEs are confirmed exploited in the wild.
Public exploits
10
10 of Arista Networks EOS's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every Arista Networks EOS version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about Arista Networks EOS vulnerabilities.
How many CVEs does Arista Networks EOS have?
Arista Networks EOS has 71 published CVE records since 2014.
How many Arista Networks EOS CVEs are in CISA KEV?
Yes — 3 of Arista Networks EOS's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for Arista Networks EOS vulnerabilities?
Yes — 10 of Arista Networks EOS's CVEs have a known public exploit.
Which versions of Arista Networks EOS are affected?
439 distinct Arista Networks EOS versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in Arista Networks EOS CVEs?
Arista Networks EOS's CVEs most often map to these CWE weakness types: CWE-284 (Improper Access Control), CWE-400 (Uncontrolled Resource Consumption), CWE-401 (Missing Release of Memory after Effective Lifetime), CWE-1284 (Improper Validation of Specified Quantity in Input).
How many critical Arista Networks EOS vulnerabilities are there?
Arista Networks EOS has 12 critical and 28 high-severity CVEs.
What is the average severity of Arista Networks EOS CVEs?
The average CVSS base score across Arista Networks EOS's scored CVEs is 7.1.