216.73.216.6

CVE-2025-8873

· Published 04/06/2026 23:16 · Modified 05/06/2026 15:02

Labels: CVE-2025-8873 2026-06-04CVE-2025-8873CWE-1286[email protected]

Essential information

Published
04/06/2026 23:16
Modified
05/06/2026 15:02
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
arista / eos cpe:2.3:a:arista:eos:*:*:*:*:*:*:*:*

References