Denial of Service Vulnerability in EOS Switches Connected to CVX Servers by Arista
CVE-2025-5089

7.1HIGH

What is CVE-2025-5089?

A vulnerability exists in Arista's EOS switches when connected to CVX servers, making them susceptible to denial of service attacks through malformed messages. The issue occurs when either device receives improperly formatted TCP packets, causing the Sysdb agent on the EOS device to crash and necessitating a soft reset, or the CVX server to experience instability due to its own agent crashes. Without proper safeguards, an attacker with high-privileged access could exploit this behavior, resulting in service disruption within the CVX cluster. It's important to note that EOS switches not connected to a CVX server remain unaffected.

Affected Version(s)

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.34.0F <= 4.34.1F

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.33.0M <= 4.33.4M

EOS / CloudVision eXchange (CVX) CloudVision eXchange 4.32.0M <= 4.32.6M

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.