Back

MEDIUM

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired

Published Oct 29, 2025

Description

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired

Affected products

Remediation

Vendor solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. Fixed versions are as follows for each product:

Danz Monitoring Fabric

* DMF 8.7.1 and later releases in the 8.7.x train * DMF 8.6.2 and later releases in the 8.6.x train * DMF 8.5.3 and later releases in the 8.5.x train * DMF 8.4.6 and later releases in the 8.4.x train.

Converged Cloud Fabric

* CCF 6.2.5 and later releases in the 6.2.x train

Cloud Vision Appliance

* CVA 7.1.0 and later releases in the CVA 7.x train

Multi-Cloud Director

* MCD 2.4.1 and later releases in the 2.4.x train

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Arista
Published Oct 29, 2025
Updated Oct 30, 2025
Reserved Jul 24, 2025

CISA Vulnrichment

Updated Oct 30, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Arista
Published Oct 29, 2025
Updated Oct 30, 2025

GitHub

No data