CVE-2025-8873
On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-1286
- Published
- 2026-06-04
- Last modified
- 2026-06-05
Affected products
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2026-83611 — xmldom: Parser silently accepts a not-well-formed end tag whose name is followed by a line break and trailing content
- CVE-2026-72916 — Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses
- CVE-2026-0931 — Denial-of-service vulnerability in M-Files Server
- CVE-2026-25292 — Improper Validation of Syntactic Correctness of Input in Automotive Linux OS
- CVE-2026-57026 — Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash
- CVE-2026-55767 — Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
- CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges
- CVE-2019-25720 — Dräger SC Monitoring Devices DoS via Malformed Network Packet