Impact
On Arista EOS platforms that have MLAG Dual Primary Detection enabled, a transmitter may send specially crafted packets that corrupt the dual‑primary state. A unauthenticated attacker who can reach the dual-primary detection segment can cause the secondary MLAG controller to incorrectly assume a dual‑primary condition, resulting in its interfaces being err‑disabled. This leads to a denial of connectivity for the affected networks while the primary switch continues to operate. The flaw exposes only availability, not confidentiality or integrity, and scopes to systems with MLAG Dual Primary Detection configured.
Affected Systems
The vulnerability affects Arista Networks EOS devices with MLAG Dual Primary Detection. Specific firmware or patch levels are not enumerated in the advisory, so all EOS releases that support this feature are potentially vulnerable. No explicit version range is supplied.
Risk and Exploitability
The CVSS score of 7.0 classifies the issue as high severity. The EPSS score is below 1 %, indicating a very low likelihood of exploitation at present, and it is not listed in CISA’s KEV catalog. Nonetheless, an attacker with local network access to the dual‑primary detection segment can craft and send packets without authentication to trigger the err‑disable logic. The risk is that a device outage can occur once the primary switch fails, as the secondary fails to recover. The attack vector is network‑based local access, requiring no credentials and minimal skill beyond packet crafting.
OpenCVE Enrichment