Description
A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (temporary multicast traffic loss)
Action: Immediate Patch
AI Analysis

Impact

A specially crafted network packet can cause the premature removal of multicast forwarding state on affected interfaces. The resulting disappearance of multicast routing entries leads to a temporary loss of multicast traffic during the affected period. This vulnerability can disrupt multicast‑based services such as streaming, conferencing, or discovery protocols, affecting availability for users who rely on continuous multicast delivery.

Affected Systems

Arista Networks EOS firmware versions before 4.33.9M in the 4.33.x train, before 4.34.8M in the 4.34.x train, before 4.35.6M in the 4.35.x train, and before 4.36.2F in the 4.36.x train are vulnerable. Applying any of the listed later releases removes the flaw.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high‑severity. The EPSS score of less than 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending a crafted multicast packet over the network to trigger the state expiration. No user‑local privilege or authentication is required, and the vulnerability affects the integrity of multicast routing tables but not system credentials or data confidentiality.

Generated by OpenCVE AI on September 18, 2026 at 09:46 UTC.

Remediation

Vendor Solution

The following EOS releases contain the fix: - 4.33.9M and later in the 4.33.x train - 4.34.8M and later in the 4.34.x train - 4.35.6M and later in the 4.35.x train - 4.36.2F and later in the 4.36.x train No hotfixes are available for this issue.


Vendor Workaround

There is no mitigation available to address this vulnerability.


OpenCVE Recommended Actions

  • Update the EOS firmware to 4.33.9M or later for the 4.33.x train, 4.34.8M or later for the 4.34.x train, 4.35.6M or later for the 4.35.x train, or 4.36.2F or later for the 4.36.x train.
  • If an immediate upgrade cannot be performed, restrict or filter untrusted multicast traffic through the affected interfaces until a patch is available, as no workaround exists.
  • Continuously monitor multicast traffic on the network to detect and respond to any sudden loss of multicast streams that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 09:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentially resulting in temporary multicast traffic loss during the affected period.
Title Security Advisory 0175
Weaknesses CWE-670
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T13:37:56.689Z

Reserved: 2026-08-12T16:47:18.121Z

Link: CVE-2026-73468

cve-icon Vulnrichment

Updated: 2026-09-16T13:37:52.217Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:52.383

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-73468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:00:06Z

Weaknesses
  • CWE-670

    Always-Incorrect Control Flow Implementation