CVE-2026-77190: Security Advisory 0177

Published Sep 16, 2026
·
Updated

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service.

Affected Software

1 affected component
Arista Networks Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.34.8M
  2. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.35.6M
  3. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.36.2F

Event History

Sep 16, 2026
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices are exposed to this denial-of-service condition?

Affected Arista EOS platforms are exposed when both PIM Sparse Mode and MLAG are configured on the device. The attacker must be network-adjacent to the switch and able to connect to it.

2

Does exploitation require credentials or user interaction?

No. The advisory describes exploitation by an unauthenticated attacker, with no user interaction required.

3

What is the operational impact of repeated exploitation?

Malformed messages can cause the Pimsm agent to terminate unexpectedly. Although the agent restarts automatically, repeated attacks can force continuous restarts and create a sustained denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203