Executive brief
Arista CloudVision eXchange (CVX), a platform used to manage and coordinate network switch states, is vulnerable to a denial-of-service attack. An attacker with high-level access to a connected network switch can send malformed messages that cause the CVX software to crash. This results in instability across the CVX cluster, potentially disrupting network management operations and visibility.
Technical details
The vulnerability is classified as Improper Input Validation (CWE-20) within Arista CloudVision eXchange (CVX). The CVX agent fails to properly handle unexpected or malformed TCP messages sent from a connected switch. An attacker who has already gained high-privilege access to a switch within the network can exploit this by sending custom TCP packets to the CVX manager. This causes the CVX agent to crash, leading to a Denial of Service (DoS) and instability of the CVX cluster. The attack requires low-level network reachability (PR:L) but high-privilege access on the originating switch to craft the necessary traffic.
Affected products
- Arista Networks CloudVision eXchange (CVX)
Timeline
- 2026-06-05: advisory: Security advisory published by Arista Networks