CVE-2026-73451
Received Received - Intake

Arista EOS Shared SVI Security ACL Failure on Dual Switch Cards

Vulnerability report for CVE-2026-73451, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with dual switch cards and ingress Security ACLs configured on shared SVIs. Restarting the secondary switchcard forwarding agent or inserting a secondary switchcard can cause security ACLs to stop working, leading to incorrect packet filtering behavior.

Detection Guidance

This vulnerability is specific to Arista EOS with dual switch cards and ingress Security ACLs on shared SVIs. Detection requires verifying ACL functionality after restarting the secondary switchcard forwarding agent or inserting the secondary switchcard. Check if ACLs on shared SVIs permit or deny packets incorrectly.

Impact Analysis

The vulnerability may cause security ACLs to fail, allowing unauthorized network traffic or blocking legitimate traffic incorrectly. This could disrupt network operations or expose sensitive data if ACLs are meant to enforce security policies.

Compliance Impact

The vulnerability may lead to incorrect packet permit/deny behavior due to security ACLs failing on shared SVIs. This could potentially result in unauthorized data access or transmission, which may impact compliance with standards like GDPR (data protection) or HIPAA (healthcare data privacy).

Mitigation Strategies

Verify if your Arista EOS devices use dual switch cards with ingress Security ACLs on shared SVIs. If affected, avoid restarting the secondary switchcard forwarding agent or inserting secondary switchcards until a patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73451. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart