CNNVD-202508-2919 Information

CNNVD ID

CNNVD-202508-2919

CVE-2025-3456

  • CNNVD Published: 2025-08-25

Description (Chinese)

Arista EOS是美国Arista公司的一个完全可编程的、高度模块化的、基于Linux的网络操作系统。 Arista EOS存在安全漏洞,该漏洞源于全局通用加密密钥配置可能以明文形式记录,可能导致协议特定密码泄露。

Description (English)

Arista EOS is a fully programmable, highly modular, Linux-based network operating system of the American company Arista. There is a security loophole in Arista EOS, which stems from the fact that the global generic encryption key configuration may be recorded in explicit form and may lead to the disclosure of the specific password of the agreement.

Hazard Level

Critical

Vulnerability Type

其他

Affected Vendor

Arista

Published

2025-08-25

Last Modified

2026-02-24

References

https://www.arista.com/en/support/advisories-notices/security-advisory/22022-security-advisory-0122 https://nvd.nist.gov/vuln/detail/CVE-2025-3456

Patch

https://www.arista.com/en/support/advisories-notices/security-advisory/22022-security-advisory-0122

Share on: