Impact
The vulnerability occurs on Arista EOS platforms that run dual switch cards and use ingress Security ACLs on shared Switched Virtual Interfaces (SVI). When the secondary switchcard switchcard is inserted, the ACLs applied to SVIs stop functioning, causing packets that should be denied to be permitted or vice versa. This weakness is categorized as CWE‑1419.
Affected Systems
All Arista EOS releases prior to the remediated versions are affected. The affected releases include any 4.36.x older than 4.36.1F, any 4.35.x older than 4.35.5M, any 4.34.x older than 4.34.7M, and any 4.33.x older than 4.33.9M. The issue applies to devices that support dual switch cards with shared‑mode SVIs and have ingress Security ACLs configured.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. The EPSS score is < 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need privileged access to perform a restart of the secondary switchcard or insert a new card, conditions that are typically controlled by network operators. No malicious exploitation has been reported in customer networks, so the risk to an attacker is largely theoretical at this time, though the potential impact of disabling ACL enforcement could allow unauthorized traffic if the condition is triggered.
OpenCVE Enrichment