Record summary

CVE-2025-7048 has a selected CVSS score of 5.3 (medium).

Description

On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List4.34.3.0 to ≤ 4.34.3.1Maffected
4.33.0 to ≤ 4.33.5Maffected
4.32.0 to ≤ 4.32.7Maffected
4.31.0 to ≤ 4.31.9Maffected
Before 4.30.0affected

References

2