CVE-2026-73462
massOut-of-Bounds Read in Arista EOS IGMP Snooping Agent Enables Adjacent Multicast DoS
Arista EOS switches running IGMP snooping (enabled by default on all VLANs) contain an out-of-bounds read flaw (CWE-125) in the IGMP snooping agent. A network-adjacent, unauthenticated attacker can trigger it by sending malformed packets onto an affected VLAN, causing the snooping agent to terminate unexpectedly. The impact is availability-focused: while the agent is down, multicast traffic management is disrupted and multicast traffic may be flooded to all ports of the affected VLAN, and repeated exploitation can prolong the loss of intended multicast forwarding. Any environment running Arista EOS where untrusted devices share a VLAN with multicast traffic is affected, notably data center, campus, and multi-tenant networks. As of now there is no evidence of exploitation in the wild, no known public proof-of-concept, and the issue is not listed in CISA's KEV catalog.
What to do: Check Arista's security advisory (assigned by [email protected]) for the fixed EOS release for your train and upgrade, since no fixed version can be confirmed from the available data. Until then, restrict untrusted layer-2 access to VLANs with IGMP snooping enabled (e.g., port security, ACLs, limiting guest/tenant access), and monitor device logs for unexpected IGMP snooping agent restarts as an indicator of attempted exploitation.
| Arista Networks EOS (Extensible Operating System) with IGMP snooping enabled (default on all VLANs) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected VLAN to cause the IGMP snooping agent to terminate unexpectedly. This results in a temporary disruption of multicast traffic management, which may cause multicast traffic to be flooded to all ports of the affected VLAN until the service recovers. Repeated exploitation could result in a prolonged loss of intended multicast forwarding behavior.
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.