Arista EOS Vulnerability Affecting IPsec Traffic Processing
CVE-2025-8873
8.7HIGH
What is CVE-2025-8873?
A vulnerability has been identified in Arista EOS systems configured with IPsec, where a specifically crafted packet can halt the processing of all IPsec traffic. While the control plane may recognize this issue and attempt to reset the processing pipeline for IPsec, traffic does not always resume correctly after the reset. Importantly, non-IPsec traffic remains unaffected by this issue, as does IPsec traffic that is not originating from or terminating on the system. This vulnerability was brought to attention by an Arista customer.
Affected Version(s)
EOS 7020SRG Series 4.33.0M <= 4.33.4M
EOS 7020SRG Series 4.32.0M <= 4.32.6.1M
EOS 7020SRG Series 4.31.0M <= 4.31.7.1M
