Impact
A flaw in the IGMP snooping agent on Arista EOS allows an unauthenticated attacker to send malformed IGMP packets on a VLAN where snooping is enabled, causing the agent to crash. The crash temporarily disables multicast traffic management, resulting in multicast packets being flooded to every port of the affected VLAN until the service recovers. Repeated exploitation can keep the system in this flooded state for prolonged periods, effectively disrupting normal multicast forwarding.
Affected Systems
All Arista EOS platforms running with IGMP snooping enabled on any VLAN are affected. Versions older than 4.36.2F, 4.35.6M, 4.34.8M, and 4.33.9M are vulnerable; the vulnerability applies to the default configuration where IGMP snooping is enabled on every VLAN.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity, and the EPSS score of less than 1 percent suggests a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a network‑adjacent attacker able to inject malformed packets into the VLAN; no authentication is required. Consequently, any device on the same VLAN could trigger the crash, making the issue a real risk in environments with unrestricted VLAN access.
OpenCVE Enrichment