Junglewise Threat Intelligence

CVE-2026-2379: Arista EOS IPsec sequence number mismatch in hardware-supported platforms

CVE-2026-2379 · Severity: medium · CVSS 5.9 · Published 2026-06-05

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS, the operating system for Arista network switches, contains a flaw in how it handles secure encrypted connections (IPsec) on certain hardware. Under specific conditions like network interface resets, the system may fail to properly synchronize security settings between devices. This can lead to unstable network communications and potentially impact the confidentiality or availability of data moving through the encrypted tunnel.

Technical details

A vulnerability in Arista EOS on platforms with hardware IPsec support can lead to a 'Resource Operation after Expiration or Release' (CWE-672) condition. When specific IPsec features are enabled, physical interface flaps or certain agent restarts can trigger a tunnel re-establishment that incorrectly utilizes existing Security Associations (SAs). This results in sequence number mismatches between the tunnel endpoints. An attacker or network instability can leverage this to cause communication failures or potentially intercept traffic due to the weakened state of the security association. The vulnerability is tracked as CVE-2026-2379 and has a CVSS 3.1 score of 5.9 (Medium) due to the high complexity required for exploitation.

Affected products

  • Arista EOS

Timeline

  • 2026-06-05: advisory: Initial advisory published by Arista and NVD

References

Related threats