nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-7048 CVE-2025-7048
MEDIUM
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption o
Record summary
CVE-2025-7048 has a selected CVSS score of 5.3 (medium).
Description
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 4.34.3.0 to ≤ 4.34.3.1M | affected |
| 4.33.0 to ≤ 4.33.5M | affected | ||
| 4.32.0 to ≤ 4.32.7M | affected | ||
| 4.31.0 to ≤ 4.31.9M | affected | ||
| Before 4.30.0 | affected |
References
2arista.com
https://www.arista.com/en/support/advisories-notices/security-advisory/23120-security-advisory-0132