Denial of Service Vulnerability in Arista EOS Products by Arista Networks
CVE-2026-77190

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-77190?

On platforms operating Arista EOS, a vulnerability exists allowing an unauthenticated attacker, positioned on the same network, to exploit configurations of PIM Sparse Mode with MLAG. By sending specially crafted messages, the attack can lead to the unexpected termination of the Pimsm agent. Although the system automatically restarts the Pimsm agent, persistent attacks can cause a cycle of continuous restarts, ultimately resulting in a denial of service and impacting network performance.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.2F <= 4.34.7M

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.