Arista EOS Vulnerability Affecting IPsec Traffic Processing
CVE-2025-8873

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
4 June 2026

What is CVE-2025-8873?

A vulnerability has been identified in Arista EOS systems configured with IPsec, where a specifically crafted packet can halt the processing of all IPsec traffic. While the control plane may recognize this issue and attempt to reset the processing pipeline for IPsec, traffic does not always resume correctly after the reset. Importantly, non-IPsec traffic remains unaffected by this issue, as does IPsec traffic that is not originating from or terminating on the system. This vulnerability was brought to attention by an Arista customer.

Affected Version(s)

EOS 7020SRG Series 4.33.0M <= 4.33.4M

EOS 7020SRG Series 4.32.0M <= 4.32.6.1M

EOS 7020SRG Series 4.31.0M <= 4.31.7.1M

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.