Arista NetworksCVE-2026-77190
Arista Networks EOS: denial of service
Medium6.0CVE-2026-77190 · Published Sep 16, 2026
On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.36.0F, <= 4.36.1F | No fix yet |
| >= 4.35.0F, <= 4.35.5M | No fix yet | |
| >= 4.34.2F, <= 4.34.7M | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-20
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | Arista Networks EOS: remote code execution | Critical9.2 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 16 | Arista Networks EOS: out-of-bounds read | High7.1 | No fix yet |
| Sep 16 | Arista Networks EOS: secrets in logs | Low2.1 | No fix yet |
| Sep 16 | Arista Networks EOS: denial of service | Medium5.3 | No fix yet |
| Sep 16 | Arista Networks VeloCloud Edge: missing authentication | High8.7 | 5.2.0.0+3 more |