Executive brief
Arista EOS network switches with dual switch cards can lose ACL (access control list) enforcement on virtual interfaces after secondary switch card restart or insertion. ACLs are critical security controls that govern which network traffic is allowed or blocked; when they malfunction, unauthorized traffic may reach protected networks or legitimate traffic may be incorrectly blocked, breaking both security and availability.
Technical details
This is a resource initialization vulnerability (CWE-1419) affecting ingress security ACLs on Switched Virtual Interfaces (SVIs) configured in shared mode on Arista EOS switches with dual switch cards. When the secondary switch card forwarding agent restarts or the secondary switch card is inserted, the shared ACL resource becomes desynchronized and ACL enforcement stops functioning. Exploitation requires: (1) dual switch card configuration, (2) security ACL configured on SVI in ingress direction with shared ACL identifier, and (3) a secondary switch card restart or insertion event. The impact is incorrect packet filtering—traffic that should be denied may be permitted and vice versa. Patches are available in later EOS releases (4.36.1F+, 4.35.5M+, 4.34.7M+, 4.33.9M+, 4.32.12M+, 4.31.11M+); mitigation involves removing and reapplying ACL configuration.
Affected products
- Arista EOS 4.36.0.1F and below (4.36.x), 4.35.4M and below (4.35.x), 4.34.6M and below (4.34.x), 4.33.8M and below (4.33.x), 4.32.11M and below (4.32.x), 4.31.1F to 4.31.10M (4.31.x)
Timeline
- 2026-09-09: disclosed: Security Advisory 0151 initial release
- 2026-09-22: other: CSAF JSON file added to advisory