8.3
CVE-2024-47519 - Backup uploads to ETM subject to man-in-the-middle interception
Backup uploads to ETM subject to man-in-the-middle interception
6.4
CVE-2024-47518 - Specially constructed queries targeting ETM could discover active remote access sessions
Specially constructed queries targeting ETM could discover active remote access sessions
6.8
CVE-2024-47517 - Expired and unusable administrator authentication tokens can be revealed by units that have timed oβ¦
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
8.3
CVE-2024-9134 - Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced reβ¦
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
6.6
CVE-2024-9133 - A user with administrator privileges is able to retrieve authentication tokens
A user with administrator privileges is able to retrieve authentication tokens
8.1
CVE-2024-9132 - The administrator is able to configure an insecure captive portal script
The administrator is able to configure an insecure captive portal script
7.2
CVE-2024-9131 - A user with administrator privileges can perform command injection
A user with administrator privileges can perform command injection
4.6
CVE-2024-7142 - On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardwareβ¦
On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on them
6.5
CVE-2024-5872 - On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might β¦
On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, which may cause incorrect control plane behavior related to the packet, such as route flaps, multicast routes learnt, etc.
4.3
CVE-2024-7095 - On affected platforms running Arista EOS with SNMP configured, if βsnmp-server transmit max-sizeβ iβ¦
On affected platforms running Arista EOS with SNMP configured, if βsnmp-server transmit max-sizeβ is configured, under some circumstances a specially crafted packet can cause the snmpd process to leak memory. This may result in the snmpd process being terminated (causing SNMP requests to time out uβ¦