CVE-2026-77190: Security Advisory 0177
On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
Which devices are exposed to this denial-of-service condition?
Affected Arista EOS platforms are exposed when both PIM Sparse Mode and MLAG are configured on the device. The attacker must be network-adjacent to the switch and able to connect to it.
Does exploitation require credentials or user interaction?
No. The advisory describes exploitation by an unauthenticated attacker, with no user interaction required.
What is the operational impact of repeated exploitation?
Malformed messages can cause the Pimsm agent to terminate unexpectedly. Although the agent restarts automatically, repeated attacks can force continuous restarts and create a sustained denial of service.