Arista NetworksCritical EOS and VeloCloud vulnerabilities (CVSS 10) create remediation and service obligations for Arista customers before any incremental revenue.
Arista Networks released a batch of security advisories on September 9, turning an advance warning into an immediate customer maintenance task, with critical vulnerabilities affecting EOS and VeloCloud. Arista's updated summary lists critical EOS gNPSI and P4Runtime vulnerabilities with CVSS v3.1 scores of 10, alongside other findings, and customers must assess the conditions and remediation for their own environments. Cisco Systems' September 4 security commentary describes the broader problem, saying vulnerability discovery is accelerating beyond customers' ability to remediate it, and its September 2 advisories already include critical issues involving IOS XR and Nexus 9000 switches using Silicon One, with customers directed to fixed software. Cisco says it scanned 1.8 billion lines of code across 25 languages in eight weeks using frontier models, while Arista's May statement said AI-assisted testing caught complex flaws before software release. For both Cisco Systems and Arista Networks, the investment question is whether suppliers can keep expanding AI networks without letting the cost and disruption of securing them erode customer confidence, since finding defects creates engineering and service obligations before it creates incremental revenue.
Arista NetworksCritical EOS and VeloCloud vulnerabilities (CVSS 10) create remediation and service obligations for Arista customers before any incremental revenue.
Cisco Systems IncCisco's own critical IOS XR and Nexus 9000 advisories and accelerating vulnerability discovery add engineering and service burden on its AI networking customers.