PT-2025-23043 · Arista · Arista Eos
Published
2025-05-27
·
Updated
2025-05-28
·
CVE-2025-2826
CVSS v3.1
2.6
Low
| Vector | AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Arista EOS (affected versions not specified)
Description
On affected platforms running Arista EOS, ACL policies may not be enforced. This issue affects IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces, resulting in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The symptoms of this issue include packets that should be permitted being dropped and packets that should be dropped being permitted.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arista Eos