Description
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Ingress Security ACLs cease to function on shared SVIs after secondary switchcard restart or insertion
Action: Apply patch
AI Analysis

Impact

The vulnerability occurs on Arista EOS platforms that run dual switch cards and use ingress Security ACLs on shared Switched Virtual Interfaces (SVI). When the secondary switchcard switchcard is inserted, the ACLs applied to SVIs stop functioning, causing packets that should be denied to be permitted or vice versa. This weakness is categorized as CWE‑1419.

Affected Systems

All Arista EOS releases prior to the remediated versions are affected. The affected releases include any 4.36.x older than 4.36.1F, any 4.35.x older than 4.35.5M, any 4.34.x older than 4.34.7M, and any 4.33.x older than 4.33.9M. The issue applies to devices that support dual switch cards with shared‑mode SVIs and have ingress Security ACLs configured.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. The EPSS score is < 1 %, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need privileged access to perform a restart of the secondary switchcard or insert a new card, conditions that are typically controlled by network operators. No malicious exploitation has been reported in customer networks, so the risk to an attacker is largely theoretical at this time, though the potential impact of disabling ACL enforcement could allow unauthorized traffic if the condition is triggered.

Generated by OpenCVE AI on September 20, 2026 at 14:23 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73451 has been fixed in the following releases: * 4.36.1F and later releases in the 4.36.x train. * 4.35.5M and later releases in the 4.35.x train. * 4.34.7M and later releases in the 4.34.x train. * 4.33.9M and later releases in the 4.33.x train.


Vendor Workaround

The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs. For every SVI check the active ACL(s) applied to it, switch(config)# interface VlanNNN switch(config-if-VlNNN)# show active   Then remove the ACL(s) and re-apply them, switch(config-if-VlNNN)# no ip access-group <acl name> in switch(config-if-VlNNN)# ip access-group <acl name> in switch(config-if-VlNNN)# no ipv6 access-group <acl name> in switch(config-if-VlNNN)# ipv6 access-group <acl name> in   Note: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs. For more information about Security ACLs see EOS User Manual: ACLs and Route Maps https://www.arista.com/en/um-eos/eos-acls-and-route-maps .


OpenCVE Recommended Actions

  • Upgrade the Arista EOS firmware to a remediated software version – 4.36.1F or later in the 4.36.x train4.35.x, 4.34.x, or 4.33.x train.
  • Re‑configure all ingress IPv4 and IPv6 ACLs applied to SVIs by removing and reapplying them as described in the workaround.
  • Avoid restarting the secondary switchcard or inserting a new card until the ACLs have been re‑applied, and monitor switch logs for ACL disablement messages.

Generated by OpenCVE AI on September 20, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Title On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can
Weaknesses CWE-1419
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-15T19:24:42.924Z

Reserved: 2026-08-12T16:42:47.921Z

Link: CVE-2026-73451

cve-icon Vulnrichment

Updated: 2026-09-15T19:24:39.313Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:38.960

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-73451

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-1419

    Incorrect Initialization of Resource