Executive brief
Arista EOS switches with MLAG (Multi-chassis Link Aggregation) dual-primary detection enabled are vulnerable to network-based packet injection attacks. An attacker on the same network segment can send specially crafted packets to disrupt the detection mechanism, causing the secondary switch to incorrectly declare a dual-primary condition and disable all its interfaces, resulting in immediate traffic loss.
Technical details
The vulnerability stems from insufficient verification of data authenticity (CWE-345) in the MLAG dual-primary detection mechanism. An unauthenticated attacker with access to the dual primary detection network segment (UDP heartbeat interface) can craft and send packets that interfere with the state detection logic. When the primary MLAG peer fails or becomes unreachable while attack packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and executes the configured action (typically err-disabling all interfaces), causing service disruption. The attack requires the target switches to have MLAG with dual-primary detection configured and the heartbeat interface exposed to the attacker's network segment. No patch is currently mentioned in the advisory; mitigation involves ACL-based network isolation of the heartbeat interface.
Affected products
- Arista EOS 4.36.1F and below (4.36.x train); 4.35.5M and below (4.35.x train); 4.34.7.1M and below (4.34.x train); 4.33.9M and below (4.33.x train); all prior releases
Timeline
- 2026-09-09: disclosed: Security Advisory 0161 initial release
- 2026-09-22: advisory: Revision 1.1: CSAF JSON file added