IGMP Snooping Vulnerability in Arista EOS Affects Network Traffic Management
CVE-2026-73462
7.1HIGH
What is CVE-2026-73462?
A vulnerability exists in Arista EOS when IGMP snooping is enabled by default on all VLANs. This flaw allows a network-adjacent unauthenticated attacker to send malformed packets, potentially causing the IGMP snooping agent to fail unexpectedly. As a result, multicast traffic management is disrupted, leading to multicast traffic flooding on all ports within the affected VLAN until recovery of the service. Continuous exploitation could further prolong the malfunctioning of multicast traffic forwarding, significantly impacting network performance and reliability.
Affected Version(s)
EOS 710 Series 4.36.0 <= 4.36.1F
EOS 710 Series 4.35.0 <= 4.35.5M
EOS 710 Series 4.34.0 <= 4.34.7.1M
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered internally by Arista.
