Ingress ACL Policy Bypass in Arista EOS Platforms
CVE-2025-2826

2.6LOW

Key Information:

Status
Vendor
CVE Published:
27 May 2025

What is CVE-2025-2826?

The vulnerability allows for improper enforcement of Access Control List (ACL) policies on platforms running Arista EOS. Specifically, enabled IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL on Ethernet or Link Aggregation Group (LAG) interfaces may malfunction, leading to potential security risks. This defect can result in the erroneous allowance or denial of incoming packets, with permitted packets unexpectedly being dropped and denied packets being incorrectly allowed, compromising network integrity.

Affected Version(s)

EOS EOS 4.33.2F

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.