9 results (0.004 seconds)

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

On affected platforms running Arista MOS, the configuration of a BGP password will cause the password to be logged in clear text that can be revealed in local logs or remote logging servers by authenticated users, as well as appear in clear text in the device’s running config. En las plataformas afectadas que ejecutan Arista MOS, la configuración de una contraseña BGP hará que la contraseña se registre en texto plano que los usuarios autenticados pueden revelar en registros locales o servidores de registro remotos, además de aparecer en texto plano en la configuración en ejecución del dispositivo. • https://www.arista.com/en/support/advisories-notices/security-advisory/18644-security-advisory-0090 • CWE-319: Cleartext Transmission of Sensitive Information •

CVSS: 7.5EPSS: 0%CPEs: 101EXPL: 0

On the affected platforms running EOS, a malformed DHCP packet might cause the DHCP relay agent to restart. • https://www.arista.com/en/support/advisories-notices/security-advisory/17445-security-advisory-0087 • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 8.8EPSS: 0%CPEs: 113EXPL: 1

On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision • https://www.arista.com/en/support/advisories-notices/security-advisory/17250-security-advisory-0086 • CWE-284: Improper Access Control CWE-863: Incorrect Authorization •

CVSS: 9.6EPSS: 0%CPEs: 2EXPL: 0

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior releases En el software MOS (Sistema Operativo Metamako) de Arista, compatible con la línea de productos 7130, en determinadas condiciones, la autenticación es omitida por usuarios no privilegiados que acceden a la Interfaz de Usuario web. Este problema afecta a: Sistema Operativo Arista Metamako versión MOS-0.34.0 y versiones anteriores • https://www.arista.com/en/support/advisories-notices/security-advisories/12916-security-advisory-68 • CWE-287: Improper Authentication •

CVSS: 8.4EPSS: 0%CPEs: 2EXPL: 0

In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, a user may be able to execute commands despite not having the privileges to do so. This issue affects: Arista Metamako Operating System All releases in the MOS-0.1x train MOS-0.32.0 and prior releases En el software MOS (Sistema Operativo Metamako) de Arista, que es compatible con la línea de productos 7130, en determinadas condiciones, un usuario puede ejecutar comandos a pesar de no tener los privilegios para hacerlo. Este problema afecta: Sistema Operativo Arista Metamako Todas las versiones MOS-0.1x train MOS-0.32.0 y anteriores • https://www.arista.com/en/support/advisories-notices/security-advisories/12915-security-advisory-67 • CWE-287: Improper Authentication •