← All vendors
Vendor
Arista
Security vulnerabilities in Arista products, including the VeloCloud Orchestrator SD-WAN platform. Management-plane flaws in SD-WAN infrastructure carry broad network impact across every connected site.
CVEs
[ CRITICAL ]CVSS 10.0EPSS 0.9%kev
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Arista / VeloCloud Orchestrator On-Prem
[ MEDIUM ]CVSS 5.8EPSS 1.1%kev
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
Arista / Extensible Operating System
