Impact
A specially crafted network packet can cause the premature removal of multicast forwarding state on affected interfaces. The resulting disappearance of multicast routing entries leads to a temporary loss of multicast traffic during the affected period. This vulnerability can disrupt multicast‑based services such as streaming, conferencing, or discovery protocols, affecting availability for users who rely on continuous multicast delivery.
Affected Systems
Arista Networks EOS firmware versions before 4.33.9M in the 4.33.x train, before 4.34.8M in the 4.34.x train, before 4.35.6M in the 4.35.x train, and before 4.36.2F in the 4.36.x train are vulnerable. Applying any of the listed later releases removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high‑severity. The EPSS score of less than 1% indicates a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker sending a crafted multicast packet over the network to trigger the state expiration. No user‑local privilege or authentication is required, and the vulnerability affects the integrity of multicast routing tables but not system credentials or data confidentiality.
OpenCVE Enrichment