CVE-2025-6188

7.5

Arista Networks · EOS

Arista EOS may accept maliciously formed UDP packets with source port 3503, potentially causing unexpected service behavior due to a lack of authentication.

Executive summary

A vulnerability in Arista EOS allows unauthenticated attackers to send malformed UDP packets to port 3503, which may disrupt network services or cause unexpected system behavior.

Vulnerability

This is an improper neutralization of input during web page generation or similar processing, specifically involving UDP port 3503 used for LspPing Echo Reply. The vulnerability is accessible to unauthenticated remote attackers who can send crafted packets that the system processes without sufficient authentication checks.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk that could lead to significant operational disruption. Because the affected service handles network traffic, successful exploitation may result in unauthorized state changes or denial of service for critical network functions, impacting overall infrastructure stability and availability.

Remediation

Immediate Action: Upgrade Arista EOS to version 4.34.0 or later, or to 4.33.2 or later, as specified in the official Arista security advisory.

Proactive Monitoring: Monitor network logs for unusual UDP traffic targeting port 3503 and investigate any unexpected system behavior or service interruptions.

Compensating Controls: Implement Access Control Lists (ACLs) to restrict traffic to UDP port 3503 from untrusted sources until the software patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for network-level disruption and the ease of access for remote, unauthenticated attackers, this vulnerability should be treated with high urgency. Administrators are advised to prioritize the scheduled maintenance window to apply the vendor-provided firmware updates across all affected network devices to eliminate the risk of exploitation.

More Arista Networks CVEs

Sources

Originally found and disclosed by This issue was discovered externally and responsibly reported to Arista by Chris Laffin of automattic.com., per the CVE Program record.