CVE-2026-73451: On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.9M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.7M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.1F
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Exposure is limited to affected platforms running Arista EOS with dual switch cards, ingress Security ACLs configured on SVIs in shared mode, and a restart of the secondary switchcard forwarding agent or insertion of a secondary switchcard.
What event can trigger the ACL failure?
Restarting the secondary switchcard forwarding agent or inserting a secondary switchcard can cause Security ACLs on shared SVIs to stop functioning.
What is the operational impact if the issue occurs?
Packet permit and deny behavior may be incorrect because the Security ACLs on the affected shared SVIs may no longer function.
Is malicious exploitation known to have occurred?
No. Arista states that it is not aware of malicious exploitation of this vulnerability in customer networks.