PT-2026-46407 · Arista · Eos

CVE-2025-8873

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description On platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition and attempt to reset the IPsec processing pipeline, but traffic may not resume being processed after the reset. This issue does not impact non-IPsec traffic or IPsec traffic that does not originate or terminate on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8873

Affected Products

Eos