Denial of Service Vulnerability in CVX Product by Arista Networks
CVE-2025-5090

7.1HIGH

What is CVE-2025-5090?

The CVX product from Arista Networks is susceptible to a vulnerability that arises from its insufficient handling of unexpected messages from a network-connected switch. This flaw leads to potential agent crashes within the CVX system, which can destabilize the entire CVX cluster. An attacker with high-privilege access to the connected switch could exploit this weakness by sending specially crafted TCP packets, thus creating a scenario that results in service disruptions and denial of access to legitimate users.

Affected Version(s)

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.34.0F <= 4.34.1F

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.33.0M <= 4.33.4M

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.32.0M <= 4.32.6M

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.