Executive brief
Arista EOS switches and CVX servers are vulnerable to a denial-of-service condition when communicating within a CVX cluster. An attacker with high-privilege access to a connected device can send specially crafted messages that cause the switch to reset or the management cluster to become unstable. This can lead to temporary network disruptions and loss of management capabilities for the affected infrastructure.
Technical details
The vulnerability is classified as improper input validation (CWE-20) within the communication protocol between Arista EOS switches and CVX servers. When a malformed message is received, it can trigger a Sysdb agent crash on the EOS device, resulting in a soft reset, or cause agent crashes on the CVX server, leading to cluster instability. Exploitation requires the attacker to have high-privileged access to a device already participating in the CVX cluster to inject custom TCP packets. Only EOS switches actively connected to a CVX server are impacted; standalone switches are not vulnerable.
Affected products
- Arista Networks EOS
- Arista Networks CloudVision eXchange (CVX)
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory