# CVE-2026-73451

## Summary

- **CVE ID:** CVE-2026-73451
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1419
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

## Affected Products

- Arista Networks — EOS (4.36.0)
- Arista Networks — EOS (4.35.0)
- Arista Networks — EOS (4.34.0)
- Arista Networks — EOS (4.33.0)
- Arista Networks — EOS (4.32.0)
- Arista Networks — EOS (4.31.1F)

## References

- [CNA](https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.18%
- **EPSS Percentile:** 7.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._