Arista NetworksCVE-2026-73469
Arista Networks EOS: improper authorization
Medium6.9CVE-2026-73469 · Published Sep 16, 2026
When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.35.0F, <= 4.35.4M | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Arista Networks EOS: remote code execution | Critical9.2 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 16 | Arista Networks EOS: out-of-bounds read | High7.1 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Low2.1 | No fix yet |
| Sep 16 | Arista Networks EOS: denial of service | Medium5.3 | No fix yet |
| Sep 16 | Arista Networks VeloCloud Edge: missing authentication | High8.7 | 5.2.0.0+3 more |