CVE-2024-12378: Arista Networks Cloudvision Portal
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in packets being sent over the secure Vxlan tunnels in the clear.
Affected products
- Arista Networks Cloudvision Portal: from 4.32.0, up to and including 4.32.2F; from 4.31.0, up to and including 4.31.6M; from 4.30.0, up to and including 4.30.8M; from 4.29.0, up to and including 4.29.9M; from 4.28.0, up to and including 4.28.12M; from 4.27.0, up to and including 4.27.12M
Published 2025-05-08. Last modified 2026-06-17.