CVE-2025-2826
Estado: AplazadaBaja (2.6)—
n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The two symptoms of this issue on the affected release and platform are:
Detalles técnicos trazas, registros y código del informe original
* Packets which should be permitted may be dropped and, * Packets which should be dropped may be permitted.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.52%
- Percentil entre todas las CVEs puntuadas: 42
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1284
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-2826",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-2826",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-28T13:33:59.901353Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@arista.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 2.6,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "psirt@arista.com",
"affectedData": [
{
"vendor": "Arista Networks",
"product": "EOS",
"versions": [
{
"status": "affected",
"version": "4.33.2F",
"versionType": "custom"
}
],
"platforms": [
"EOS"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-05-27T23:15:21.400",
"references": [
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/21414-security-advisory-0120",
"source": "psirt@arista.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@arista.com",
"description": [
{
"lang": "en",
"value": "CWE-1284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "n affected platforms running Arista EOS, ACL policies may not be enforced. IPv4 ingress ACL, MAC ingress ACL, or IPv6 standard ingress ACL enabled on one or more ethernet or LAG interfaces may result in ACL policies not being enforced for ingress packets. This can cause incoming packets to incorrectly be allowed or denied. The two symptoms of this issue on the affected release and platform are:\n\n * Packets which should be permitted may be dropped and,\n * Packets which should be dropped may be permitted."
},
{
"lang": "es",
"value": "En las plataformas afectadas que ejecutan Arista EOS, es posible que no se apliquen las políticas ACL. La activación de las ACL de entrada IPv4, MAC o IPv6 estándar en una o más interfaces Ethernet o LAG puede provocar que no se apliquen las políticas ACL para los paquetes entrantes. Esto puede provocar que los paquetes entrantes se permitan o denieguen incorrectamente. Los dos síntomas de este problema en la versión y plataforma afectadas son: * Los paquetes que deberían permitirse podrían descartarse y * Los paquetes que deberían descartarse podrían permitirse."
}
],
"lastModified": "2026-06-17T09:07:41.017",
"sourceIdentifier": "psirt@arista.com"
}