{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73450","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:42:47.921Z","datePublished":"2026-09-16T02:32:45.999Z","dateUpdated":"2026-09-17T17:41:33.537Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T02:32:45.999Z"},"title":"Security Advisory 0161","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-141","descriptions":[{"lang":"en","value":"CAPEC-141 Message Spoofing"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7.1M","versionType":"custom"},{"status":"affected","version":"4.33.0","lessThanOrEqual":"4.33.9M","versionType":"custom"},{"status":"affected","version":"0.0.0","lessThan":"4.33.0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24717-security-advisory-0161","name":"Security Advisory 0161","tags":["vendor-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H"}}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73450, all of the following conditions must be met:\n\n\n  *  MLAG must be configured\n  *  domain-id and peer-link are active\n  *  UDP heartbeat peer address must be configured\n  *  dual-primary detection must be configured with action errdisable all-interfaces\n\n\n\n\n\n\nBoth peers must have this configuration applied to be vulnerable.\n\n\n\nExample vulnerable configuration:\n\n\n\nswitch(config)# mlag\nswitch(config-mlag)# peer-link port-channel 10\nswitch(config-mlag)# domain-id mlagDomain\nswitch(config-mlag)# peer-address heartbeat 172.30.118.190\nswitch(config-mlag)# dual-primary detection delay 5 action errdisable all-interfaces\n\n\n\nExample show command output for vulnerable configuration:\n\n\n\nswitch# show mlag    \nMLAG Configuration:\ndomain-id         :         mlagDomain\nlocal-interface   :           Vlan4094\npeer-address      :           10.0.0.2\npeer-link         :     Port-Channel10\nhb-peer-address   :     172.30.118.190\n \nMLAG Status:\nstate             :             Active\n… \nMLAG ports:\n…\n \nMLAG Detailed Status:\n…\nDual-primary detection delay         :                   5\nDual-primary action                  :      errdisable-all\nDual-primary recovery delay          :                   0\nDual-primary non-mlag recovery delay :                   0","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73450, all of the following conditions must be met:<br></p><ol><li><span>MLAG must be configured</span></li><li>domain-id and peer-link are active</li><li>UDP heartbeat peer address must be configured</li><li>dual-primary detection must be configured with action errdisable all-interfaces</li></ol><p></p><p>Both peers must have this configuration applied to be vulnerable.</p><p>Example vulnerable configuration:</p><pre>switch(config)# mlag\nswitch(config-mlag)# peer-link port-channel 10\nswitch(config-mlag)# domain-id mlagDomain\nswitch(config-mlag)# peer-address heartbeat 172.30.118.190\nswitch(config-mlag)# dual-primary detection delay 5 action errdisable all-interfaces</pre><p>Example show command output for vulnerable configuration:</p><pre>switch# show mlag&nbsp;&nbsp;&nbsp;&nbsp;\nMLAG Configuration:\ndomain-id &nbsp; &nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; mlagDomain\nlocal-interface &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Vlan4094\npeer-address&nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.0.0.2\npeer-link &nbsp; &nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; Port-Channel10\nhb-peer-address &nbsp; : &nbsp; &nbsp; 172.30.118.190\n \nMLAG Status:\nstate &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Active\n…&nbsp;\nMLAG ports:\n…\n \nMLAG Detailed Status:\n…\nDual-primary detection delay &nbsp; &nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 5\nDual-primary action&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; :&nbsp; &nbsp; &nbsp; errdisable-all\nDual-primary recovery delay&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0\nDual-primary non-mlag recovery delay : &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0</pre>"}]}],"workarounds":[{"lang":"en","value":"Restrict access to the MLAG heartbeat interface by configuring Access Control Lists (ACLs) to permit traffic strictly from the designated peer address.\n\n\n\nInsert the following ACL rules into the top of the ingress ACL on the VRF where the heartbeat address is configured, while denying traffic from all other source addresses.\n\n\n\npermit udp host <heartbeatPeerAddress> any eq mlag\npermit udp any any eq mlag ttl eq 255\ndeny udp any any eq mlag log\n\n\n\nEnsure administrative access for required services (e.g., SSH, NTP, SNMP) remains permitted.\n\n\n\nFor instance, if the heartbeat address is reachable via the management VRF. First, construct the ingress ACL to restrict access on the MLAG heartbeat interface.\n\n\n\nswitch(config)#ip access-list MLAG-HEARTBEAT-PROTECT\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#5 permit udp host 172.30.118.190 any eq mlag\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#6 permit udp any any eq mlag ttl eq 255\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#7 deny udp any any eq mlag log\n...\n\n\n\nApply the ACL to management VRF:\n\n\n\nswitch(config)#system control-plane\nswitch(config-system-cp)#ip access-group MLAG-HEARTBEAT-PROTECT vrf management in\nswitch(config-system-cp)#exit\n\n\n\nShow command to confirm the rules:\n\n\n\nswitch(config)#show ip access-lists MLAG-HEARTBEAT-PROTECT\nPhone ACL bypass: disabled\nIP Access List MLAG-HEARTBEAT-PROTECT\n        5 permit udp host 172.30.118.190 any eq mlag\n        6 permit udp any any eq mlag ttl eq 255\n        7 deny udp any any eq mlag log\n        …\n \n        Total rules configured: …\n        Configured on Ingress: control-plane(management VRF)\n        Active on     Ingress: control-plane(management VRF)","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Restrict access to the MLAG heartbeat interface by configuring Access Control Lists (ACLs) to permit traffic strictly from the designated peer address.</p><p>Insert the following ACL rules into the top of the ingress ACL on the VRF where the heartbeat address is configured, while denying traffic from all other source addresses.</p><pre>permit udp host &lt;heartbeatPeerAddress&gt; any eq mlag\npermit udp any any eq mlag ttl eq 255\ndeny udp any any eq mlag log</pre><p>Ensure administrative access for required services (e.g., SSH, NTP, SNMP) remains permitted.</p><p>For instance, if the heartbeat address is reachable via the management VRF. First, construct the ingress ACL to restrict access on the MLAG heartbeat interface.</p><pre>switch(config)#ip access-list MLAG-HEARTBEAT-PROTECT\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#5 permit udp host 172.30.118.190 any eq mlag\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#6 permit udp any any eq mlag ttl eq 255\nswitch(config-acl-MLAG-HEARTBEAT-PROTECT)#7 deny udp any any eq mlag log\n...</pre><p>Apply the ACL to management VRF:</p><pre>switch(config)#system control-plane\nswitch(config-system-cp)#ip access-group MLAG-HEARTBEAT-PROTECT vrf management in\nswitch(config-system-cp)#exit</pre><p>Show command to confirm the rules:</p><pre>switch(config)#show ip access-lists MLAG-HEARTBEAT-PROTECT\nPhone ACL bypass: disabled\nIP Access List MLAG-HEARTBEAT-PROTECT\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;5 permit udp host 172.30.118.190 any eq mlag\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;6 permit udp any any eq mlag ttl eq 255\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;7 deny udp any any eq mlag log\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;…\n \n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Total rules configured: …\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Configured on Ingress: control-plane(management VRF)\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Active on &nbsp; &nbsp; Ingress: control-plane(management VRF)</pre>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience.</p>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","type":"finder"}],"source":{"advisory":"0161","discovery":"UNKNOWN","defects":["BUG1852792"]},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T17:41:23.594863Z","id":"CVE-2026-73450","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T17:41:33.537Z"}}]}}