← All Advisories

Arista EOS crafted IPsec packet halts dataplane processing and traffic may not resume after reset

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2025-8873

Key Details

CVECVE-2025-8873
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Classified asCWE-1286 (Improper Validation of Syntactic Correctness of Input)

What to Know

On affected platforms running Arista EOS with IPsec configured, a specially crafted packet can cause the dataplane to stop processing all IPsec traffic. The control plane may detect this condition, and attempt to reset the IPsec processing pipeline. After reset traffic may not resume being processed. There is no impact to non-IPsec traffic or to IPsec traffic not originating or terminating on the system. This issue was reported by an Arista customer. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-8873
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-8873