PT-2025-23043 · Arista · Arista Eos

Published

2025-05-27

·

Updated

2025-05-28

·

CVE-2025-2826

CVSS v3.1

2.6

Low

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Arista EOS (affected versions not specified)
Description On affected platforms running Arista EOS, ACL policies may not be enforced. This issue affects IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces, resulting in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The symptoms of this issue include packets that should be permitted being dropped and packets that should be dropped being permitted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-2826

Affected Products

Arista Eos