CVE-2026-2379 Details
Description
On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface flaps and certain agent restarts can cause IPsec tunnel re-establishment with existing Security Associations, resulting in sequence number mismatches between tunnel endpoints potentially causing unstable communication.
A vulnerability exists in Arista EOS on platforms with hardware IPsec support, specifically in certain versions and trains, where certain IPsec features are enabled. The issue arises when physical interface flaps or certain agent restarts cause IPsec tunnels to be re-established with existing Security Associations. This can lead to sequence number mismatches between tunnel endpoints, potentially causing unstable communication. The vulnerability is present in several Arista EOS-based products, including the 7280R3 and 7800R3 series with IPsec, as well as the AWE 5000 and 7000 series with IPsec. To be vulnerable, the IPsec anti-replay detection feature must be disabled, which is not the default setting.
Users are advised to upgrade to Arista EOS versions 4.35.0F, 4.34.4M, 4.33.6M, 4.32.8M, or 4.31.10M. For more information on upgrading, consult the EOS User Manual: Upgrades and Downgrades.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.arista.com/en/support/advisories-notices/security-advisory/23419-security-advisory-0134 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-672 | Operation on a Resource after Expiration or Release | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | New CVE Received | [email protected] |