ZeroHour

CVE-2026-73462

mass

Out-of-Bounds Read in Arista EOS IGMP Snooping Agent Enables Adjacent Multicast DoS

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

Arista EOS switches running IGMP snooping (enabled by default on all VLANs) contain an out-of-bounds read flaw (CWE-125) in the IGMP snooping agent. A network-adjacent, unauthenticated attacker can trigger it by sending malformed packets onto an affected VLAN, causing the snooping agent to terminate unexpectedly. The impact is availability-focused: while the agent is down, multicast traffic management is disrupted and multicast traffic may be flooded to all ports of the affected VLAN, and repeated exploitation can prolong the loss of intended multicast forwarding. Any environment running Arista EOS where untrusted devices share a VLAN with multicast traffic is affected, notably data center, campus, and multi-tenant networks. As of now there is no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.

What to do: Check Arista's security advisory (assigned by [email protected]) for the fixed EOS release for your train and upgrade, since no fixed version can be confirmed from the available data. Until then, restrict untrusted layer-2 access to VLANs with IGMP snooping enabled (e.g., port security, ACLs, limiting guest/tenant access), and monitor device logs for unexpected IGMP snooping agent restarts as an indicator of attempted exploitation.

Affected
Arista Networks EOS (Extensible Operating System) with IGMP snooping enabled (default on all VLANs)
Estimated exposure
massplausibly hundreds of thousands of Arista EOS switch installations (IGMP snooping is on by default), though only VLAN-adjacent hosts can exploit it — Arista is a top-tier data center and campus switching vendor with cumulative EOS switch deployments well into the six-to-seven figure range, and the flaw's default-on configuration means essentially the whole install base shares the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.

Weakness
CWE-125
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.