Junglewise Threat Intelligence

CVE-2026-73450: Arista EOS MLAG dual-primary detection packet injection

CVE-2026-73450 · Severity: medium · CVSS 6.9 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS switches with MLAG (Multi-chassis Link Aggregation) dual-primary detection enabled are vulnerable to network-based packet injection attacks. An attacker on the same network segment can send specially crafted packets to disrupt the detection mechanism, causing the secondary switch to incorrectly declare a dual-primary condition and disable all its interfaces, resulting in immediate traffic loss.

Technical details

The vulnerability stems from insufficient verification of data authenticity (CWE-345) in the MLAG dual-primary detection mechanism. An unauthenticated attacker with access to the dual primary detection network segment (UDP heartbeat interface) can craft and send packets that interfere with the state detection logic. When the primary MLAG peer fails or becomes unreachable while attack packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and executes the configured action (typically err-disabling all interfaces), causing service disruption. The attack requires the target switches to have MLAG with dual-primary detection configured and the heartbeat interface exposed to the attacker's network segment. No patch is currently mentioned in the advisory; mitigation involves ACL-based network isolation of the heartbeat interface.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x train); 4.35.5M and below (4.35.x train); 4.34.7.1M and below (4.34.x train); 4.33.9M and below (4.33.x train); all prior releases

Timeline

  • 2026-09-09: disclosed: Security Advisory 0161 initial release
  • 2026-09-22: advisory: Revision 1.1: CSAF JSON file added

References

Related threats