Denial of Service Vulnerability in CVX Product by Arista Networks
CVE-2025-5090
7.1HIGH
Key Information:
- Vendor
Arista Networks
- Vendor
- CVE Published:
- 5 June 2026
What is CVE-2025-5090?
The CVX product from Arista Networks is susceptible to a vulnerability that arises from its insufficient handling of unexpected messages from a network-connected switch. This flaw leads to potential agent crashes within the CVX system, which can destabilize the entire CVX cluster. An attacker with high-privilege access to the connected switch could exploit this weakness by sending specially crafted TCP packets, thus creating a scenario that results in service disruptions and denial of access to legitimate users.
Affected Version(s)
EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.34.0F <= 4.34.1F
EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.33.0M <= 4.33.4M
EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.32.0M <= 4.32.6M
