IPSec Vulnerability in Arista EOS Affecting Hardware Support
CVE-2026-2379

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
5 June 2026

What is CVE-2026-2379?

On platforms utilizing hardware IPSec support with Arista EOS, certain enabled IPSec features may lead to unexpected behavior during specific operational scenarios. This issue can arise following physical interface disruptions or specific agent restarts, which may lead to the re-establishment of IPSec tunnels alongside pre-existing Security Associations. Such conditions can create sequence number mismatches between the tunnel endpoints, ultimately causing communication instability within the network. For further information, refer to the vendor advisory on this security issue.

Affected Version(s)

EOS 7280R3 Series with IPsec (DCS-7280SR3AK 4.34.0 <= 4.34.3M

EOS 7280R3 Series with IPsec (DCS-7280SR3AK 4.33.0M <= 4.33.5M

EOS 7280R3 Series with IPsec (DCS-7280SR3AK 4.32.0M <= 4.32.7M

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.