CVE-2026-73451
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.18%
- CWE
- CWE-1419
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2026-21913 — Junos OS: EX4000: A high volume of traffic destined to the device leads to a crash and restart
- CVE-2025-24495 — Incorrect initialization of resource in the branch prediction unit for some Intel(R) Core™ Ultra Processors may allow an
- CVE-2023-5078 — A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privilege
- CVE-2026-33773 — Junos OS: EX Series, QFX Series: If the same egress filter is configured on both an IRB and a physical interface one of those is not applied
- CVE-2024-0103 — CVE
- CVE-2023-45085 — When compute hosts are disabled and reenabled, they immediately transition to "ON", not "INIT"
- CVE-2024-57375 — Andamiro Pump It Up 20th Anniversary (aka Double X or XX/2019) 1.00.0-2.08.3 allows a physically proximate attacker to c