CVE-2025-8872

MEDIUM

Arista EOS 4.31.0-4.34.0 - Denial of Service via OSPFv3 Packet Processing

Title source: llm
STIX 2.1

Description

On affected platforms running Arista EOS with OSPFv3 configured, a specially crafted packet can cause the OSFPv3 process to have high CPU utilization which may result in the OSFPv3 process being restarted. This may cause disruption in the OSFPv3 routes on the switch. This issue was discovered internally by Arista and is not aware of any malicious uses of this issue in customer networks.

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (5)
Arista Networks/EOS < 4.31.0
Arista Networks/EOS 4.31.0 - 4.31.8M
Arista Networks/EOS 4.32.0 - 4.32.7M
Arista Networks/EOS 4.33.0 - 4.33.4M
Arista Networks/EOS 4.34.0 - 4.34.1F
Published Dec 16, 2025
Tracked Since Feb 18, 2026