Impact
The vulnerability occurs on Arista EOS platforms that use dual switch cards with ingress Security ACLs configured on Switched Virtual Interfaces (SVIs) in shared mode. When the secondary switchcard forwarding agent is restarted or a secondary switchcard is inserted, the ACLs on shared SVIs cease to function. This results in packets being incorrectly permitted or denied, potentially allowing traffic that should be blocked to pass. The weakness is classified as CWE‑1419.
Affected Systems
All Arista EOS releases supporting dual switch cards with shared‑mode SVIs are affected if they run an older version before the remediated releases. The affected releases include any 4.36.x version prior to 4.36.1F, any 4.35.x prior to 4.35.5M, any 4.34.x prior to 4.34.7M, and any 4.33.x prior to 4.33.9M. Users should verify if their device firmware meets one of those affected versions.
Risk and Exploitability
The CVSS score is 6.3, indicating medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The CVE description notes that a restart of the secondary switchcard forwarding agent or insertion of a secondary switchcard can disable ACLs, but it does not specify how an attacker could trigger these actions or what level of privileges would be required. No malicious exploitation has been reported in customer networks. Therefore, while the impact could allow unauthorized traffic if the ACLs are disabled, the exploitability for an attacker is unknown based on the supplied information.
OpenCVE Enrichment