Impact
Arista EOS devices that run PIM Sparse Mode and MLAG can be targeted by an unauthenticated attacker who is network‑adjacent to the switch. By sending malformed PIM packets the attacker forces the Pimsm agent to crash. The operating system automatically restarts the agent, but repeated exploits can bring the agent into a restart loop, denying the device’s PIM functionality and causing a sustained denial of service to the network segment using that switch.
Affected Systems
The vulnerability affects Arista Networks EOS releases 4.36.2F and later in the 4.36.x train, 4.35.6M and later in the 4.35.x train, and 4.34.8M and later in the 4.34.x train. No hotfix is available and no temporary workaround exists.
Risk and Exploitability
The CVSS rating of 6 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the switch on a network segment must be adjacent to it, and only those network links or interfaces that support PIM Sparse Mode and MLAG provide the attack surface. When the conditions are met, the attacker can repeatedly supply crafted PIM messages to keep the Pimsm agent in a crash‑restart cycle, resulting in a measurable denial of service.
OpenCVE Enrichment