CVE-2025-5090: Arista Networks Eos / Cloudvision Exchange Cvx

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to have a high privilege access to the connected switch to be able to send custom TCP packets to the CVX.

Affected products

  • Arista Networks Eos / Cloudvision Exchange Cvx: from 4.34.0F, up to and including 4.34.1F; from 4.33.0M, up to and including 4.33.4M; from 4.32.0M, up to and including 4.32.6M; from 4.31.0, before 4.32.0 (fixed in 4.32.0); from 4.30.0, before 4.31.0 (fixed in 4.31.0)

Published 2026-06-05. Last modified 2026-10-07.