CVE-2026-73462

Summary

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0 <= 4.36.1Faffected
Arista NetworksEOS4.35.0 <= 4.35.5Maffected
Arista NetworksEOS4.34.0 <= 4.34.7.1Maffected
Arista NetworksEOS4.33.0 <= 4.33.8Maffected

Weaknesses

  • CWE-125: CWE-125 Out-of-bounds Read

Workarounds

There is no mitigation or workaround available. Disabling IGMP snooping will NOT mitigate the issue.

References