CVE-2025-54547 Details
Description
On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
A vulnerability exists in multiple Arista products, including Danz Monitoring Fabric, Converged Cloud Fabric, CloudVision Appliance, and Multi-Cloud Director. When SSH session multiplexing is enabled on the client side, SSH sessions that are multiplexed onto the same channel can continue to perform file-system operations after the session has timed out. This issue arises from insufficient session expiration, allowing operations to be carried out even when a session is no longer active.
Users are advised to upgrade to the latest versions of the respective products that address this vulnerability. For Danz Monitoring Fabric, versions 8.7.1, 8.6.2, 8.5.3, and 8.4.6 are recommended. Converged Cloud Fabric users should upgrade to version 6.2.5 or later. For CloudVision Appliance, version 7.1.0 or later is recommended, and Multi-Cloud Director users should upgrade to version 2.4.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 29, 2025CISA-ADP
Assessed Oct 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/22538-security-advisory-0124 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | CISA-ADP |
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Arista DANZ Monitoring Fabric | All versions |
CPE
Remediation
| |
| Arista Converged Cloud Fabric | All versions |
CPE
Remediation
| |
| Arista CloudVision Appliance | All versions |
CPE
Remediation
| |
| Arista Multi-Cloud Director | All versions |
CPE
Remediation
| |
| Arista CloudVision DCA-350E-CV | All versions |
CPE
Remediation
| |
| Arista CloudVision DCA-300-CV | All versions |
CPE
Remediation
| |
| Arista CloudVision DCA-250-CV | All versions |
CPE
Remediation
| |
| Arista CloudVision DCA-200-CV | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | CVE Modified | CISA-ADP |
| Oct 29, 2025 | New CVE Received | [email protected] |
Volerion