0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Critical Vulnerability in Arista EOS Allows System Data Manipulation (heise.de)

· 31d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Critical flaw (CVE-2026-11705) in Arista EOS allows system data manipulation if TerminAttrRW is enabled
  • Arista released EOS version 4.36.1F; more patches announced
  • Additional vulnerabilities: CVE-2026-52896 (high), CVE-2026-52895 and CVE-2026-12546 (medium)
  • No active exploitation known; disable TerminAttr as temporary mitigation

"A critical vulnerability (CVE-2026-11705) in Arista EOS allows attackers to manipulate system data under certain conditions. Affected are routers and switches in cloud and data center environments. The flaw is only exploitable if the TerminAttrRW option is enabled, which is not the default setting. Arista has released an update for version 4.36.1F; patches for older versions are in progress. Additional vulnerabilities were reported, including a high-severity (CVE-2026-52896) and two medium-severity (CVE-2026-52895, CVE-2026-12546). Administrators are advised to disable the Streaming Telemetry Agent until patches are available."

Discussion Matrix

0 segments

no comments yet.