CVE-2025-7048: Arista Networks Eos
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with MACsec configuration, a specially crafted packet can cause the MACsec process to terminate unexpectedly. Continuous receipt of these packets with certain MACsec configurations can cause longer term disruption of dataplane traffic.
Affected products
- Arista Networks Eos: from 4.34.3.0, up to and including 4.34.3.1M; from 4.33.0, up to and including 4.33.5M; from 4.32.0, up to and including 4.32.7M; from 4.31.0, up to and including 4.31.9M; before 4.30.0 (fixed in 4.30.0)
Published 2026-01-06. Last modified 2026-10-07.