CVE-2025-5089
Last modified
CVE-2025-5089 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain malformed messages received from the connected EOS switch. This leads to either a Sysdb agent crash on the EOS device causing a soft reset of the switch or agent crashes on the CVX server causing instability of the CVX cluster. An attacker could use this behavior to create a denial of service (DoS) scenario. Note that this would require the attacker to already have a high privilege access to the connected device to be able to send custom TCP packets. EOS switches that are not connected to a CVX server are not impacted.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Arista Networks | EOS / CloudVision eXchange (CVX) | >= 4.34.0F, <= 4.34.1F; >= 4.33.0M, <= 4.33.4M; >= 4.32.0M, <= 4.32.6M; >= 4.31.0M, <= 4.31.8M; >= 4.30.0, < 4.31.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-5089?
How severe is CVE-2025-5089?
How do I fix CVE-2025-5089?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-50869A stored Cross-Site Scripting (XSS) vulnerability exists in …6.1
- CVE-2025-5087Kaleris NAVIS N4 ULC (Ultra Light Client) communicates insec…6
- CVE-2025-50870Institute-of-Current-Students 1.0 is vulnerable to Incorrect…9.8
- CVE-2025-50879Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2025-5088An authenticated Redis session could be used to obtain full …8.7
- CVE-2025-50881The `flow/admin/moniteur.php` script in Use It Flow administ…8.8
- CVE-2025-50891The server-side backend for Adform Site Tracking before 2025…7.2
- CVE-2025-50892The eudskacs.sys driver version 20250328 shipped with EaseUs…7.8
- CVE-2025-50897A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2…4.3
- CVE-2025-5090CVX is not resilient to unexpected messages from a connected…7.1
- CVE-2025-50900An issue was discovered in getrebuild/rebuild 4.0.4. The aff…9.8
- CVE-2025-50901JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19)…9.8
Are you affected by CVE-2025-5089?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
