CVE-2025-5088
Last modified
CVE-2025-5088 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Arista Networks | EOS / CloudVision eXchange (CVX) | >= 4.34.0F, <= 4.34.1F; >= 4.33.0M, <= 4.33.4M; >= 4.32.0M, <= 4.32.6M; >= 4.31.0M, <= 4.31.8M; >= 4.30.0, < 4.31.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-5088?
How severe is CVE-2025-5088?
How do I fix CVE-2025-5088?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-50867A SQL Injection vulnerability exists in the takeassessment2.…6.5
- CVE-2025-50868A SQL Injection vulnerability exists in the takeassessment2.…6.5
- CVE-2025-50869A stored Cross-Site Scripting (XSS) vulnerability exists in …6.1
- CVE-2025-5087Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insec…6
- CVE-2025-50870Institute-of-Current-Students 1.0 is vulnerable to Incorrect…9.8
- CVE-2025-50879Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2025-50881The `flow/admin/moniteur.php` script in Use It Flow administ…8.8
- CVE-2025-5089In a CVX cluster, an EOS switch connected to a CVX server is…7.1
- CVE-2025-50891The server-side backend for Adform Site Tracking before 2025…7.2
- CVE-2025-50892The eudskacs.sys driver version 20250328 shipped with EaseUs…7.8
- CVE-2025-50897A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2…4.3
- CVE-2025-5090CVX is not resilient to unexpected messages from a connected…7.1
Are you affected by CVE-2025-5088?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
