Junglewise Threat Intelligence

CVE-2026-73469: Arista EOS loose uRPF verification bypass

CVE-2026-73469 · Severity: medium · CVSS 5.8 · Published 2026-09-16

Executive brief

Arista EOS network switches contain a flaw in loose Unicast Reverse Path Forwarding (uRPF) configuration that allows certain traffic to bypass intended security checks and be forwarded when it should be dropped. This affects specific Arista switch platforms and could allow unauthorized traffic to traverse the network, potentially exposing internal systems or bypassing network security policies.

Technical details

The vulnerability is an incorrect authorization flaw (CWE-863) in Arista EOS that affects loose mode uRPF implementations on specific platforms (7050X4 and 7358X4 series). When loose uRPF is configured on an interface, the device fails to properly verify and drop traffic that does not match expected reverse path routes, allowing spoofed or unauthorized source IP traffic to be processed and forwarded. The issue requires loose mode uRPF to be explicitly configured on an interface to be exploitable; strict mode uRPF or no uRPF configuration is unaffected. Attack vector is network-based with no authentication required. Arista has not identified any active exploitation in the wild and recommends upgrading to patched EOS versions beyond 4.35.4M.

Affected products

  • Arista EOS 4.35.4M and below in 4.35.x train
  • Arista 7050X4 Series 4.35.4M and below in 4.35.x train
  • Arista 7358X4 Series 4.35.4M and below in 4.35.x train

Timeline

  • 2026-09-09: disclosed: Security Advisory 0176 initial release
  • 2026-09-22: other: CSAF JSON file added to advisory

References

Related threats