Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY75 SECURITY RECORDS

Arista Networks

EOS

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at eos, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-73462 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.8M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73462 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.9M and later releases in the 4.33.x train Update reference ↗
CVE-2026-73457 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73457 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train Update reference ↗
CVE-2026-73456 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73456 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train Update reference ↗
CVE-2026-73442 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train Update reference ↗
CVE-2026-73443 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M The recommended resolution is to upgrade to a remediated software version at your earliest convenience.; Important: Upgrading alone is not sufficient. The replay protection introduced by the fix is disabled by default and must be explicitly enabled with the following new global configuration command after upgrading to a remediated release:; switch(config)#vrrp ipv4 authentication anti-replay; CVE-2026-73443 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train Update reference ↗
CVE-2026-77190 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.2F ≤ 4.34.7M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-77190 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73468 16 Sep 2026 EOS: 1.0.0 < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7.1M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.1F The following EOS releases contain the fix:; - 4.33.9M and later in the 4.33.x train; - 4.34.8M and later in the 4.34.x train; - 4.35.6M and later in the 4.35.x train; - 4.36.2F and later in the 4.36.x train; No hotfixes are available for this issue. Update reference ↗
CVE-2026-73440 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7.1M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; Following the system upgrade, users are required to execute the syntax conversion command specified below to adopt the updated, encrypted SNMPv3 CLI format:; switch# configure convert new-syntax; The updated encrypted SNMPv3 CLI configuration follows this structure, incorporating the newly introduced "key <algo> <encrypted_text>" syntax:; switch# show running-config | grep snmp-server; snmp-server user alice group_alice v3 localized f5717f2cdde9bb946d00 auth sha256 key 7 005D110205085E520B754E1B591C504542585F557D2F217064607A10034752035500080755575640440F5C00505053515F08525208035C1605525E0A040E781F4D; CVE-2026-73440 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73469 16 Sep 2026 EOS: 4.35.0F ≤ 4.35.4M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73469 has been fixed in the following releases:; - 4.36.0F and later releases in the 4.36.x train; - 4.35.5M and later releases in the 4.35.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73453 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F < 4.34.0F, 4.32.0F < 4.33.0F, 4.31.0F < 4.32.0F, 4.30.0F < 4.31.0F, 4.29.2F < 4.30.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73453 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73455 16 Sep 2026 EOS: 1.0.0 < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.6M, 4.35.0F ≤ 4.35.4M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix:; - 4.33.9M and later in the 4.33.x train; - 4.34.7M and later in the 4.34.x train; - 4.35.5M and later in the 4.35.x train; - 4.36.1F and later in the 4.36.x train; A hotfix (version 1.0) is available for 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M. Update reference ↗
CVE-2026-73438 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73438 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73436 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7.1M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73436 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; No hotfix is available for CVE-2026-73436. Update reference ↗
CVE-2026-73435 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.9M, 1.0.0 < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73435 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.33.10M and later releases in the 4.33.x train; A hotfix is available for the following releases: 4.36.1F, 4.35.5M, 4.34.7M, 4.33.9M.; URL: https://www.arista.com/support/advisories-notices/sa-download/?sa171-SecurityAdvisory171_CVE-2026-73435.swix; SWIX hash (SHA512): 4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7; Note: Installing/uninstalling the SWIX will cause the Ospf process to restart. Update reference ↗
CVE-2026-19640 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.24.0F < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-19640 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73463 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.32.0F ≤ 4.32.11M, 4.31.0F ≤ 4.31.10M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73463 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73445 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.0.1F, 4.35.0F ≤ 4.35.5M, 4.34.0F ≤ 4.34.7M, 4.33.0F ≤ 4.33.8M, 4.32.0F < 4.33.0F, 4.31.0F < 4.32.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73445 has been fixed in the following releases:; - 4.36.1F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.33.9M and later releases in the 4.33.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-2380 16 Sep 2026 EOS: 4.36.0F ≤ 4.36.1F, 4.35.0F < 4.36.0F, 4.34.0F < 4.35.0F, 4.33.0F < 4.34.0F, < 4.33.0F The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-2380 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; No hotfix is available for this issue. Update reference ↗
CVE-2026-73464 16 Sep 2026 EOS: 4.29.0F < 4.30.0F, 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. Update reference ↗
CVE-2026-73454 16 Sep 2026 EOS: 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. Update reference ↗
CVE-2026-73439 16 Sep 2026 EOS: 4.33.2F ≤ 4.33.8M, 4.34.0F ≤ 4.34.6M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. Update reference ↗
CVE-2026-73461 16 Sep 2026 EOS: 4.29.0F < 4.30.0F, 4.30.0F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F ≤ 4.32.11M, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.8M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. Update reference ↗
CVE-2026-73447 16 Sep 2026 EOS: 4.30.2F < 4.31.0F, 4.31.0F < 4.32.0F, 4.32.0F < 4.33.0F, 4.33.0F ≤ 4.33.8M, 4.34.0F ≤ 4.34.7M, 4.35.0F ≤ 4.35.5M, 4.36.0F ≤ 4.36.0.1F The following EOS releases contain the fix for this vulnerability:; - 4.33.9M and later releases in the 4.33.x train; - 4.34.7.1M and later releases in the 4.34.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.36.1F and later releases in the 4.36.x train; No hotfix is available for this vulnerability. Update reference ↗
CVE-2026-73450 16 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M, 0.0.0 < 4.33.0 The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Update reference ↗
CVE-2026-73460 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F The recommended resolution is to upgrade to a fixed software version. Update reference ↗
CVE-2026-73459 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F The recommended resolution is to upgrade to a fixed software version. Update reference ↗
CVE-2026-73446 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M, 4.32.0 < 4.33.0F, 4.31.0 < 4.32.0F The recommended resolution is to upgrade to a fixed software version. Update reference ↗
CVE-2026-73444 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.9M, version range in vendor record The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train Update reference ↗
CVE-2026-73437 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M The recommended resolution is to upgrade to a remediated software version at your earliest convenience and enable the reply source-address validation CLI knob under dhcp relay mode:; switch(config)# dhcp relay; switch(config-dhcp-relay)# reply source-address validation; CVE-2026-73437 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train; Note: All versions require upgrading to a release containing the fix (as listed above) and applying the required configuration. Arista will not be providing any hotfixes. Update reference ↗
CVE-2026-19655 15 Sep 2026 EOS: 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 4.33.0 ≤ 4.33.9M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-19655 has been fixed in the following releases:; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.10M and later releases in the 4.33.x train Update reference ↗
CVE-2026-73458 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7M, 4.33.0 ≤ 4.33.8M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train; * 4.35.6M and later releases in the 4.35.x train; * 4.34.8M and later releases in the 4.34.x train; * 4.33.9M and later releases in the 4.33.x train Update reference ↗
CVE-2026-73467 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-73466 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-73465 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.7M, 0.0.0 ≤ 4.33.9M, ≤ 4.32.0, ≤ 4.31.0 CVE-2026-73465 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-19641 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.0F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 0.0.0 ≤ 4.33.8M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.; CVE-2026-19641 has been fixed in the following releases:; * 4.36.1F and later releases in the 4.36.x train.; * 4.35.6M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.9M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-73451 15 Sep 2026 EOS: 4.36.0 ≤ 4.36.0.1F, 4.35.0 ≤ 4.35.4M, 4.34.0 ≤ 4.34.6M, 4.33.0 ≤ 4.33.8M, 4.32.0 ≤ 4.32.11M, 4.31.1F ≤ 4.31.10M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73451 has been fixed in the following releases:; * 4.36.1F and later releases in the 4.36.x train.; * 4.35.5M and later releases in the 4.35.x train.; * 4.34.7M and later releases in the 4.34.x train.; * 4.33.9M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-75945 14 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F CVE-2026-75945 has been fixed in the following release:; * 4.36.2F and later releases in the 4.36.x train. Update reference ↗
CVE-2026-75944 14 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F CVE-2026-75944 has been fixed in the following release:; * 4.36.2F and later releases in the 4.36.x train. Update reference ↗
CVE-2026-75943 14 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M, 0.0.0 ≤ 4.33.9M CVE-2026-75943 has been fixed in the following releases:; * 4.36.2F and later releases in the 4.36.x train.; * 4.35.6M and later releases in the 4.35.x train.; * 4.34.8M and later releases in the 4.34.x train.; * 4.33.10M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-77191 14 Sep 2026 EOS: 4.35.0 ≤ 4.35.0.3F, 4.34.0 ≤ 4.34.5M, 0.0.0 ≤ 4.33.7.1M CVE-2026-77191 has been fixed in the following releases:; * 4.35.1F and later releases in the 4.35.x train.; * 4.34.6M and later releases in the 4.34.x train.; * 4.33.8M and later releases in the 4.33.x train. Update reference ↗
CVE-2026-73449 14 Sep 2026 EOS: 4.36.0 ≤ 4.36.1F, 4.35.0 ≤ 4.35.5M, 4.34.0 ≤ 4.34.7.1M The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; CVE-2026-73449 has been fixed in the following releases:; - 4.36.2F and later releases in the 4.36.x train; - 4.35.6M and later releases in the 4.35.x train; - 4.34.8M and later releases in the 4.34.x train Update reference ↗
CVE-2026-2379 5 Jun 2026 4.34.0 ≤ 4.34.3M; 4.33.0M ≤ 4.33.5M; 4.32.0M ≤ 4.32.7M; 4.31.0M ≤ 4.31.9M; 4.30.0F < 4.31.0; 4.29.0F < 4.30.0; 4.28.0F < 4.29.0; 4.27.1F < 4.28.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-8873 4 Jun 2026 4.33.0M ≤ 4.33.4M; 4.32.0M ≤ 4.32.6.1M; 4.31.0M ≤ 4.31.7.1M; 4.30.0M ≤ 4.30.10M; 4.29.0M ≤ 4.29.10.1M No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-5502 4 Jun 2026 4.31.0 ≤ 4.31.0F; 4.30.0 ≤ 4.30.4M; 4.29.0 ≤ 4.29.6M; 4.28.0 ≤ 4.28.8M; 4.27.0 ≤ 4.27.11M; 4.26.0 ≤ 4.26.11M; 4.25.0 ≤ 4.25.11M; 4.24.0 ≤ 4.24.11M No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-27892 4 Jun 2026 4.31.0 ≤ 4.31.2F; 4.30.0 ≤ 4.30.5M; 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10M; 4.27.0 ≤ 4.27.8M; 4.26.0 ≤ 4.26.9M; 4.25.0 ≤ 4.25.10M; 4.24.0 ≤ 4.24.11M No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-27890 4 Jun 2026 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10M; 4.27.0 ≤ 4.27.8M; 4.26.0 ≤ 4.26.9M; 4.25.0 ≤ 4.25.10M; 4.24.0 ≤ 4.24.11M No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-27891 4 Jun 2026 4.32.0 ≤ 4.32.0.1F; 4.31.0 ≤ 4.31.2F; 4.30.0 ≤ 4.30.6M; 4.29.0 ≤ 4.29.7M; 4.28.0 ≤ 4.28.10.1M; 4.27.2F < 4.28.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-6858 4 Jun 2026 4.31.0 ≤ 4.31.1F; 4.30.0 ≤ 4.30.5M; 4.29.0 ≤ 4.29.7M; 4.28.10 ≤ 4.28.10.1M No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-7048 6 Jan 2026 EOS: 4.34.3.0 ≤ 4.34.3.1M, 4.33.0 ≤ 4.33.5M, 4.32.0 ≤ 4.32.7M, 4.31.0 ≤ 4.31.9M, < 4.30.0 The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.; For more information about upgrading see EOS User Manual: Upgrades and Downgrades https://www.arista.com/en/um-eos/eos-upgrades-and-downgrades; CVE-2025-7048 has been fixed in the following releases:; * 4.35.0F and later releases; * 4.34.4M and later releases in the 4.34.x train; * 4.33.6M and later releases in the 4.33.x train; * 4.32.8M and later releases in the 4.32.x train; * 4.31.10M and later releases in the 4.31.x train Update reference ↗
CVE-2025-8872 16 Dec 2025 4.34.0 ≤ 4.34.1F; 4.33.0 ≤ 4.33.4M; 4.32.0 ≤ 4.32.7M; 4.31.0 ≤ 4.31.8M; ≤ 4.31.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.