Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3198 articles · 183323 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2025-8873EXPLOITEDPATCHED
arista · eos

Arista EOS Dataplane Denial of Service via Malformed IPsec Packet

Description

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.

Affected Products

VendorProductVersions
aristaeos4.33.0M, 4.32.0M, 4.31.0M, 4.30.0M, 4.29.0M

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristaeoscert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/22869-security-advisory-0127(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories59d ago
[UPDATE] [hoch] Arista EOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB59d ago
CVE-2025-8873 | Arista EOS up to 4.33.4M IPsec improper validation of syntactic correctness of input
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://www.arista.com/en/support/advisories-notices/security-advisory/22869-security-advisory-0127
CWECWE-1286
PublishedJun 4, 2026
Last enriched59d agov2
Trending Score0
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16812
VeloCloud Orchestrator OS Command Injection
Trending: 82
MEDIUMCVE-2026-7473EXPKEV
Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass
NONECVE-2024-27891EXP
On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.
NONECVE-2023-5502EXP
On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.
HIGHCVE-2025-5088
Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 4, 2026
Discovered by ZDM
Jun 4, 2026
Updated: description, affectedVersions, severity, activelyExploited
Jun 5, 2026
Actively Exploited
Jun 5, 2026
Patch Available
Jun 5, 2026

Version History

v2
Last enriched 59d ago
v2Tier C59d ago

Updated description with critical vulnerability details, added new affected versions, changed severity to CRITICAL, and noted that there is no exploit available.

descriptionaffectedVersionsseverityactivelyExploited
via VulDB
v159d ago

Initial creation