Executive brief
A vulnerability in Arista EOS network switches can allow a remote attacker to disable encrypted VPN connections. By sending a specially crafted network packet, an attacker can cause the device to stop processing all IPsec traffic, potentially leading to a permanent loss of secure connectivity until manual intervention occurs. This issue specifically affects encrypted communications and does not impact standard, unencrypted network traffic.
Technical details
A denial-of-service vulnerability exists in Arista EOS due to improper validation of syntactic correctness of input (CWE-1286) within the IPsec processing pipeline. A remote, unauthenticated attacker can trigger this condition by sending a specially crafted packet to a system where IPsec is originating or terminating. While the control plane may attempt to detect the failure and reset the pipeline, traffic may fail to resume automatically after the reset. The impact is limited to IPsec traffic; non-IPsec traffic and transit IPsec traffic not terminating on the device are unaffected.
Affected products
- Arista EOS All versions with IPsec configured
Timeline
- 2026-06-04: disclosed: Initial advisory publication by Arista Networks
- 2026-06-04: advisory: NVD record published