Junglewise Threat Intelligence

CVE-2026-77190: Arista EOS PIM Sparse Mode denial of service

CVE-2026-77190 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

Arista EOS network switches running PIM Sparse Mode with MLAG (Multi-Chassis Link Aggregation) enabled are vulnerable to a denial of service attack from network-adjacent attackers. An attacker can send crafted messages that repeatedly crash the Pimsm routing agent, causing continuous restarts and network disruption. The agent automatically restarts, but sustained attacks prevent normal network operations until patches are applied.

Technical details

This vulnerability is an improper input validation flaw (CWE-20) in the Pimsm agent that processes Protocol Independent Multicast (PIM) Sparse Mode messages. The attack vector is network-adjacent and requires no authentication or user interaction; however, exploitation requires that the target switch have both PIM Sparse Mode and MLAG explicitly configured. When an attacker sends malformed PIM messages to such a device, the Pimsm agent terminates unexpectedly, though the system automatically restarts it. Repeated attacks trigger continuous restart cycles, causing sustained denial of service. Fixed in EOS 4.36.2F, 4.35.6M, and 4.34.8M or later.

Affected products

  • Arista EOS 4.36.1F and earlier in 4.36.x train; 4.35.5M and earlier in 4.35.x train; 4.34.2F through 4.34.7M in 4.34.x train

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0177 initial release
  • 2026-09-16: advisory: CVE-2026-77190 published
  • 2026-09-09: patched: Fixes available in EOS 4.36.2F, 4.35.6M, and 4.34.8M or later

References

Related threats