Arista EOS MACsec Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Arista EOS platforms that support MACsec, including several series of Arista switches. When MACsec is configured with valid keys, a specially crafted packet can cause the MACsec process to crash unexpectedly. This disruption can lead to a longer-term interruption of dataplane traffic. The issue arises from improper handling of certain packets, causing the MACsec agent to terminate and restart, which may temporarily alleviate the problem but does not provide a permanent solution.

Impact

Exploitation of this vulnerability causes the MACsec process to crash and restart, disrupting MACsec operations and potentially leading to longer-term interruptions in dataplane traffic.

Remediation

Users are advised to upgrade to Arista EOS versions 4.35.0F, 4.34.4M, 4.33.6M, 4.32.8M, or 4.31.10M. For more information on upgrading, consult the EOS User Manual: Upgrades and Downgrades.

Added: Jan 6, 2026, 8:17 PM
Updated: Jan 6, 2026, 8:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.9
remediation
0.0
relevance
1.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.