Executive brief
Arista EOS network switches configured with Protocol Independent Multicast (PIM) Sparse Mode can be forced to drop multicast traffic by an attacker sending a specially crafted packet. The vulnerability causes temporary blackholing of multicast traffic on affected interfaces, disrupting video streaming, market data feeds, and other services that rely on multicast delivery. No mitigation is available; vendors must upgrade their EOS software.
Technical details
A control flow implementation flaw (CWE-670) in Arista EOS allows a specially crafted packet to prematurely expire multicast forwarding state on interfaces running PIM Sparse Mode (IPv4 or IPv6). An unauthenticated attacker on the same network segment as an affected interface can send this packet to cause temporary loss of multicast traffic forwarding. The vulnerability requires PIM Sparse Mode to be explicitly configured on at least one interface; platforms without this configuration are not affected. Arista recommends upgrading to patched versions: EOS 4.36.2F or later (4.36.x train), 4.35.6M or later (4.35.x train), 4.34.8M or later (4.34.x train), or 4.33.9M or later (4.33.x train). Earlier releases in each train and all 4.32.x and prior versions are vulnerable.
Affected products
- Arista EOS 4.36.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7.1M and below (4.34.x), 4.33.8M and below (4.33.x), 4.32.x and earlier
Timeline
- 2026-09-09: disclosed: Initial security advisory published by Arista
- 2026-09-22: advisory: Advisory revision 1.1 with CSAF JSON file added
- 2026-09-16: other: CVE-2026-73468 published