CVE-2025-6188
7.5Arista Networks · EOS
Arista EOS may accept maliciously formed UDP packets with source port 3503, potentially causing unexpected service behavior due to a lack of authentication.
Executive summary
A vulnerability in Arista EOS allows unauthenticated attackers to send malformed UDP packets to port 3503, which may disrupt network services or cause unexpected system behavior.
Vulnerability
This is an improper neutralization of input during web page generation or similar processing, specifically involving UDP port 3503 used for LspPing Echo Reply. The vulnerability is accessible to unauthenticated remote attackers who can send crafted packets that the system processes without sufficient authentication checks.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk that could lead to significant operational disruption. Because the affected service handles network traffic, successful exploitation may result in unauthorized state changes or denial of service for critical network functions, impacting overall infrastructure stability and availability.
Remediation
Immediate Action: Upgrade Arista EOS to version 4.34.0 or later, or to 4.33.2 or later, as specified in the official Arista security advisory.
Proactive Monitoring: Monitor network logs for unusual UDP traffic targeting port 3503 and investigate any unexpected system behavior or service interruptions.
Compensating Controls: Implement Access Control Lists (ACLs) to restrict traffic to UDP port 3503 from untrusted sources until the software patch can be applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for network-level disruption and the ease of access for remote, unauthenticated attackers, this vulnerability should be treated with high urgency. Administrators are advised to prioritize the scheduled maintenance window to apply the vendor-provided firmware updates across all affected network devices to eliminate the risk of exploitation.
More Arista Networks CVEs
Sources
Originally found and disclosed by This issue was discovered externally and responsibly reported to Arista by Chris Laffin of automattic.com., per the CVE Program record.