GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS (ingress ACL enforcement on ethernet/LAG): TENANT ISOLATION: with IPv4 ingress, MAC ingress, or IPv6

CVE-2025-2826Firmware, BMC & network fabricArista Security Advisory 0120curated

Impact

TENANT ISOLATION: with IPv4 ingress, MAC ingress, or IPv6 standard ingress ACLs applied to one or more ethernet or LAG interfaces, the policies may not be enforced at all. The third ACL-enforcement defect in the same family — worth treating Arista ingress ACLs as a control that needs periodic active verification rather than a set-and-forget boundary.

Who can reach it

Any traffic arriving on an affected interface. No attacker capability required.

What to do

EOS upgrade plus reload on affected platforms. Because ACL enforcement is the thing that fails, the only trustworthy verification is sending traffic that should be dropped and confirming it is — do that as a standing test in your fabric CI, not just after this patch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.