CVE-2025-2796: On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal
On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability.
Note: this issue does not affect VXLANSec or MACSec encryption functionality.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2796?
CVE-2025-2796 has a critical severity rating due to potential exploits that can compromise data integrity.
How do I fix CVE-2025-2796?
To mitigate CVE-2025-2796, update your Arista EOS software to the latest version that addresses this vulnerability.
What platforms are affected by CVE-2025-2796?
CVE-2025-2796 affects Arista EOS systems with hardware IPSec support and anti-replay protection configured.
What behavior does CVE-2025-2796 exhibit?
CVE-2025-2796 may lead to unexpected behavior where duplicate encrypted packets are not properly dropped.
Is there a workaround for CVE-2025-2796?
Currently, the best solution for CVE-2025-2796 is to implement software updates as no effective workarounds are recommended.