CVE-2026-73469: Security Advisory 0176
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.0F - Compensating control
For platforms using Arista EOS with a loose uRPF configuration, adjust uRPF to ensure traffic that should be dropped based on these routes is properly subjected to the intended verification drop.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue affects specific platforms running Arista EOS when loose Unicast Reverse Path Forwarding (uRPF) is configured. Deployments without that configuration are not identified as affected by the advisory data.
What would an attacker need to do to exploit it?
An attacker would need to send traffic that is expected to be dropped by loose uRPF route verification. Under the affected conditions, the device may instead process and forward that traffic.
Is there evidence of exploitation in customer networks?
Arista discovered the issue internally and states that it is not aware of malicious use in customer networks.