Description
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.

This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unintended forwarding of traffic due to loose uRPF configuration
Action: Patch
AI Analysis

Impact

The vulnerability allows traffic that should be dropped based on unicast reverse path forwarding checks to be processed and forwarded. The result is that packets from unauthorized or misrouted sources are forwarded, potentially exposing the network to unwanted traffic or service disruption. The weakness resides in insufficient enforcement of uRPF checks, a permission level degradation flaw.

Affected Systems

Affected devices are Arista EOS routers running EOS releases before 4.35.5M in the 4.35.x train or before 4.36.0F in the 4.36.x train.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate impact, and the EPSS score of less than 1% suggests a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary with network access sending permitted traffic that bypasses uRPF checks; exploitation would require crafting traffic that satisfies the loose mode constraints, which may be feasible with network-level privileges. No hotfix is available, and no workaround exists, so the only available mitigation is an upgrade.

Generated by OpenCVE AI on September 18, 2026 at 10:27 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73469 has been fixed in the following releases: - 4.36.0F and later releases in the 4.36.x train - 4.35.5M and later releases in the 4.35.x train No hotfix is available for this issue.


Vendor Workaround

No mitigation exists for this issue.


OpenCVE Recommended Actions

  • Upgrade EOS to 4.36.0F or newer or 4.35.5M or newer
  • Confirm that uRPF mode is set to strict or otherwise properly configured for your network
  • Monitor routing and forwarding logs for any unexpected traffic that would indicate bypass of uRPF checks

Generated by OpenCVE AI on September 18, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Title Security Advisory 0176
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T13:41:36.781Z

Reserved: 2026-08-12T16:47:18.121Z

Link: CVE-2026-73469

cve-icon Vulnrichment

Updated: 2026-09-16T13:41:32.256Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:52.510

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-73469

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses