SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-73451

MEDIUM · CVSS 4.8 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Arista EOS platforms with dual switch cards and configured ingress Security ACLs on shared Switched Virtual Interfaces (SVIs) are vulnerable to a malfunction where restarting the secondary switch card or inserting a new one can disable the ACLs. This may lead to improper packet filtering, potentially allowing unauthorized traffic. Organizations using affected Arista equipment should prioritize this issue to ensure network security and proper ACL functionality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73451
Severity
MEDIUM
CVSS
4.8
EPSS
0.18%

Original NVD Description

On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.