CVE-2025-8872
OSPFv3 Packet Causes High CPU, Process Restart in Arista EOS
Publication date: 2025-12-16
Last updated on: 2025-12-16
Assigner: Arista Networks, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| arista | eos | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-400 | The product does not properly control the allocation and maintenance of a limited resource. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects Arista EOS devices running OSPFv3. A specially crafted packet can cause the OSPFv3 process to consume high CPU resources, potentially leading to the OSPFv3 process restarting. This restart can disrupt OSPFv3 routing on the affected switch.
How can this vulnerability impact me? :
The vulnerability can cause high CPU utilization on the OSPFv3 process, which may lead to the process restarting. This can disrupt OSPFv3 routing on the switch, potentially causing network instability or outages in routing for devices relying on OSPFv3 on the affected switch.