CVE-2026-73462
- EPSS 0.24%
- Veröffentlicht 16.09.2026 19:17:32
- Zuletzt bearbeitet 17.09.2026 19:16:57
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause...
- EPSS 0.32%
- Veröffentlicht 16.09.2026 18:57:50
- Zuletzt bearbeitet 17.09.2026 19:16:57
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.
- EPSS 0.75%
- Veröffentlicht 16.09.2026 18:54:59
- Zuletzt bearbeitet 17.09.2026 12:18:25
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker fu...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 18:50:06
- Zuletzt bearbeitet 17.09.2026 19:16:56
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receivi...
CVE-2026-73443
- EPSS 0.27%
- Veröffentlicht 16.09.2026 18:47:30
- Zuletzt bearbeitet 17.09.2026 19:16:57
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it...
CVE-2026-77190
- EPSS 0.28%
- Veröffentlicht 16.09.2026 10:16:53
- Zuletzt bearbeitet 16.09.2026 19:08:50
On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate ...
CVE-2026-73468
- EPSS 0.25%
- Veröffentlicht 16.09.2026 09:55:17
- Zuletzt bearbeitet 16.09.2026 19:08:50
A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
CVE-2026-73440
- EPSS 0.26%
- Veröffentlicht 16.09.2026 09:55:14
- Zuletzt bearbeitet 16.09.2026 19:08:50
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configuratio...
CVE-2026-73469
- EPSS 0.29%
- Veröffentlicht 16.09.2026 09:55:14
- Zuletzt bearbeitet 16.09.2026 19:08:50
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes...
- EPSS 0.75%
- Veröffentlicht 16.09.2026 09:46:33
- Zuletzt bearbeitet 17.09.2026 04:17:59
An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is disabled b...