Description
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via multicast flooding
Action: Immediate Patch
AI Analysis

Impact

A flaw in the IGMP snooping agent on Arista EOS allows an unauthenticated attacker to send malformed IGMP packets on a VLAN where snooping is enabled, causing the agent to crash. The crash temporarily disables multicast traffic management, resulting in multicast packets being flooded to every port of the affected VLAN until the service recovers. Repeated exploitation can keep the system in this flooded state for prolonged periods, effectively disrupting normal multicast forwarding.

Affected Systems

All Arista EOS platforms running with IGMP snooping enabled on any VLAN are affected. Versions older than 4.36.2F, 4.35.6M, 4.34.8M, and 4.33.9M are vulnerable; the vulnerability applies to the default configuration where IGMP snooping is enabled on every VLAN.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity, and the EPSS score of less than 1 percent suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a network‑adjacent attacker able to inject malformed packets into the VLAN; no authentication is required. Consequently, any device on the same VLAN could trigger the crash, making the issue a real risk in environments with unrestricted VLAN access.

Generated by OpenCVE AI on September 18, 2026 at 02:43 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73462 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train * 4.33.9M and later releases in the 4.33.x train


Vendor Workaround

There is no mitigation or workaround available. Disabling IGMP snooping will NOT mitigate the issue.


OpenCVE Recommended Actions

  • Upgrade all affected EOS platforms to the fixed releases: 4.36.2F or later, 4.35.6M or later, 4.34.8M or later, and 4.33.9M or later.
  • Monitor multicast traffic for abnormal flooding patterns and review VLAN configurations to limit IGMP snooping exposure on unused or insecure VLANs.
  • Disable IGMP snooping only on VLANs where it is not required; note that disabling does not mitigate the vulnerability but can reduce the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 02:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.
Title On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the I
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T18:31:19.459Z

Reserved: 2026-08-12T16:45:03.511Z

Link: CVE-2026-73462

cve-icon Vulnrichment

Updated: 2026-09-17T18:31:11.585Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:32.630

Modified: 2026-09-17T19:16:57.380

Link: CVE-2026-73462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:52Z

Weaknesses