CVE-2026-2379: Arista Networks Eos
Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting in sequence number mismatches between tunnel endpoints potentially causing unstable communication.
Affected products
- Arista Networks Eos: from 4.34.0, up to and including 4.34.3M; from 4.33.0M, up to and including 4.33.5M; from 4.32.0M, up to and including 4.32.7M; from 4.31.0M, up to and including 4.31.9M; from 4.30.0F, before 4.31.0 (fixed in 4.31.0); from 4.29.0F, before 4.30.0 (fixed in 4.30.0); …
Published 2026-06-05. Last modified 2026-06-17.