On affected platforms with hardware IPSec support running...
Moderate severity
Unreviewed
Published
May 28, 2025
to the GitHub Advisory Database
•
Updated May 28, 2025
Description
Published by the National Vulnerability Database
May 27, 2025
Published to the GitHub Advisory Database
May 28, 2025
Last updated
May 28, 2025
On affected platforms with hardware IPSec support running Arista EOS with IPsec enabled and anti-replay protection configured, EOS may exhibit unexpected behavior in specific cases. Received duplicate encrypted packets, which should be dropped under normal anti-replay protection, will instead be forwarded due to this vulnerability.
Note: this issue does not affect VXLANSec or MACSec encryption functionality.
References