Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-5089— Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages

CVSS 6.5 · Medium EPSS 0.24% · P14

Affected Version Matrix 5

VendorProductVersion RangeStatus
Arista NetworksEOS / CloudVision eXchange (CVX)4.34.0F≤ 4.34.1Faffected
4.33.0M≤ 4.33.4Maffected
4.32.0M≤ 4.32.6Maffected
4.31.0M≤ 4.31.8Maffected
4.30.0< 4.31.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-5089

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages
Source: NVD (National Vulnerability Database)
Vulnerability Description
In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Arista CloudVision eXchange 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Arista CloudVision eXchange是美国Arista公司的一个面向数据中心和企业网络的控制平面交换平台。 Arista CloudVision eXchange存在安全漏洞,该漏洞源于EOS交换机对来自CVX服务器的特定畸形消息缺乏弹性,CVX服务器对来自EOS交换机的特定畸形消息也缺乏弹性,可能导致Sysdb代理崩溃或CVX代理崩溃,造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Arista NetworksEOS / CloudVision eXchange (CVX) 4.34.0F ~ 4.34.1F -

II. Public POCs for CVE-2025-5089

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-5089

登录查看更多情报信息。

Vendor Advisories for CVE-2025-5089 (1)

Same Patch Batch · Arista Networks · 2026-06-05 · 10 CVEs total

CVE-2025-50888.3 HIGHArista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session
CVE-2025-50906.5 MEDIUMArista CloudVision Exchange Cluster Instability via Unexpected Switch Messages
CVE-2026-256216.0 MEDIUMArista Edge Threat Management NGFW Reports Application Insecure Input Validation
CVE-2026-256226.0 MEDIUMArista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
CVE-2026-256206.0 MEDIUMArista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
CVE-2026-256236.0 MEDIUMArista Edge Threat Management NGFW UI Arbitrary Command Execution
CVE-2026-23795.9 MEDIUMArista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is D
CVE-2026-74735.8 MEDIUMArista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
CVE-2026-256245.7 MEDIUMArista Edge Threat Management NGFW UI Administrative Cross-Site Scripting

IV. Related Vulnerabilities

V. Comments for CVE-2025-5089

No comments yet


Leave a comment