CVE 7.1 HIGH

A specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted_CVE-2025-8872

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch.

This issue was discovered internally by Arista and is not aware of any malicious uses of this issue in customer networks.

Basic Information

ID CVE-2025-8872
Source Arista
Published Dec 16, 2025 at 19:32

Affected Product

Vendor Arista Networks
Product EOS
Version 4.34.0
Affected Versions Arista Networks EOS 4.34.0
Arista Networks EOS 4.33.0
Arista Networks EOS 4.32.0
Arista Networks EOS 4.31.0
Arista Networks EOS 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.