CVE-2026-73468 PUBLISHED

Security Advisory 0175

Assigner: Arista
Reserved: 12.08.2026 Published: 16.09.2026 Updated: 16.09.2026

A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
CVSS Score: 7.1

Product Status

Vendor Arista Networks
Product EOS
Versions Default: unaffected
  • affected from 1.0.0 to 4.33.0F (excl.)
  • affected from 4.33.0F to 4.33.8M (incl.)
  • affected from 4.34.0F to 4.34.7.1M (incl.)
  • affected from 4.35.0F to 4.35.5M (incl.)
  • affected from 4.36.0F to 4.36.1F (incl.)

Affected Configurations

The vulnerability is exploitable on interfaces with PIM Sparse Mode configured:

switch(config)# interface Ethernet1 switch(config-if-Et1)# pim ipv4 sparse-mode

Workarounds

There is no mitigation available to address this vulnerability.

Solutions

The following EOS releases contain the fix: - 4.33.9M and later in the 4.33.x train - 4.34.8M and later in the 4.34.x train - 4.35.6M and later in the 4.35.x train - 4.36.2F and later in the 4.36.x train

No hotfixes are available for this issue.

References

Problem Types

  • CWE-670 Always-Incorrect Control Flow Implementation CWE

Impacts

  • CAPEC-272 Protocol Manipulation