{"api_version":"1","generated_at":"2026-10-01T17:25:58+00:00","cve":"CVE-2026-73451","urls":{"html":"https://cve.report/CVE-2026-73451","api":"https://cve.report/api/cve/CVE-2026-73451.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73451","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73451"},"summary":{"title":"On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can","description":"On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-09-15 19:17:38","updated_at":"2026-09-16 19:08:50"},"problem_types":["CWE-1419 CWE-1419 Incorrect Initialization of Resource"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73451","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73451","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.36.0 4.36.0.1F custom","platforms":["755 Series","758 Series"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.35.0 4.35.4M custom","platforms":["755 Series","758 Series"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.34.0 4.34.6M custom","platforms":["755 Series","758 Series"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.33.0 4.33.8M custom","platforms":["755 Series","758 Series"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.32.0 4.32.11M custom","platforms":["755 Series","758 Series"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.31.1F 4.31.10M custom","platforms":["755 Series","758 Series"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73451 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.7M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.\n\n\n\nFor every SVI check the active ACL(s) applied to it,\n\n\n\nswitch(config)# interface VlanNNN\nswitch(config-if-VlNNN)# show active\n\n\n \n\n\n\nThen remove the ACL(s) and re-apply them,\n\n\n\nswitch(config-if-VlNNN)# no ip access-group <acl name> in\nswitch(config-if-VlNNN)# ip access-group <acl name> in\nswitch(config-if-VlNNN)# no ipv6 access-group <acl name> in\nswitch(config-if-VlNNN)# ipv6 access-group <acl name> in\n\n\n \n\n\n\nNote: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.\n\n\n\nFor more information about Security ACLs see  EOS User Manual: ACLs and Route Maps https://www.arista.com/en/um-eos/eos-acls-and-route-maps .","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"73451","cve":"CVE-2026-73451","epss":"0.001770000","percentile":"0.075190000","score_date":"2026-09-16","updated_at":"2026-09-17 00:07:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-73451","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-15T19:24:36.704643Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-15T19:24:42.924Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["755 Series","758 Series"],"product":"EOS","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"4.36.0.1F","status":"affected","version":"4.36.0","versionType":"custom"},{"lessThanOrEqual":"4.35.4M","status":"affected","version":"4.35.0","versionType":"custom"},{"lessThanOrEqual":"4.34.6M","status":"affected","version":"4.34.0","versionType":"custom"},{"lessThanOrEqual":"4.33.8M","status":"affected","version":"4.33.0","versionType":"custom"},{"lessThanOrEqual":"4.32.11M","status":"affected","version":"4.32.0","versionType":"custom"},{"lessThanOrEqual":"4.31.10M","status":"affected","version":"4.31.1F","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre><p>In order to be vulnerable to CVE-2026-73451, the following condition must be met:</p><p>Security ACL must be configured on SVI in ingress direction, which by default uses a shared ACL identifier. In the example below RACLID = 1 for both switchcards:</p><pre>switch&gt;show run interface vlan\ninterface Vlan100\n&nbsp;&nbsp;&nbsp;ip access-group acl1 in\n  \nswitch&gt;show platform trident tcam acl&nbsp;\n=== IP ACLs on switch SwitchcardCes1/0 ===\n  \nINGRESS ACL acl1 uses 2 entries\n&nbsp;&nbsp;&nbsp;&nbsp;Assigned to VLANs: 100\n&nbsp;&nbsp;&nbsp;&nbsp;Shared ACL Identifier (RACLID): 1\n&nbsp;&nbsp;&nbsp;&nbsp;Assigned to ports: None\n  \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n  \n=== IP ACLs on switch SwitchcardCes2/0 ===\n  \nINGRESS ACL acl1 uses 2 entries\n&nbsp;&nbsp;&nbsp;&nbsp;Assigned to VLANs: 100\n&nbsp;&nbsp;&nbsp;&nbsp;Shared ACL Identifier (RACLID): 1\n&nbsp;&nbsp;&nbsp;&nbsp;Assigned to ports: None\n  \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===\n</pre><div>&nbsp;</div><p>If Security ACL is <b>not</b> configured on SVI in ingress direction, there is no exposure to this issue and the message will look something like:</p><pre>switch&gt;show run interface vlan\ninterface Vlan100\n  \nswitch&gt;show platform trident tcam acl\n=== IP ACLs on switch SwitchcardCes1/0 ===\n  \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n  \n=== IP ACLs on switch SwitchcardCes2/0 ===\n  \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===</pre></pre>"}],"value":"In order to be vulnerable to CVE-2026-73451, the following condition must be met:\n\n\n\nSecurity ACL must be configured on SVI in ingress direction, which by default uses a shared ACL identifier. In the example below RACLID = 1 for both switchcards:\n\n\n\nswitch>show run interface vlan\ninterface Vlan100\n   ip access-group acl1 in\n  \nswitch>show platform trident tcam acl \n=== IP ACLs on switch SwitchcardCes1/0 ===\n  \nINGRESS ACL acl1 uses 2 entries\n    Assigned to VLANs: 100\n    Shared ACL Identifier (RACLID): 1\n    Assigned to ports: None\n  \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n  \n=== IP ACLs on switch SwitchcardCes2/0 ===\n  \nINGRESS ACL acl1 uses 2 entries\n    Assigned to VLANs: 100\n    Shared ACL Identifier (RACLID): 1\n    Assigned to ports: None\n  \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===\n\n\n \n\n\n\nIf Security ACL is not configured on SVI in ingress direction, there is no exposure to this issue and the message will look something like:\n\n\n\nswitch>show run interface vlan\ninterface Vlan100\n  \nswitch>show platform trident tcam acl\n=== IP ACLs on switch SwitchcardCes1/0 ===\n  \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n  \n=== IP ACLs on switch SwitchcardCes2/0 ===\n  \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n  \n=== IPv6 ACLs on switch SwitchcardCes2/0 ==="}],"datePublic":"2026-09-09T18:10:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n</pre>"}],"value":"On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."}],"impacts":[{"capecId":"CAPEC-180","descriptions":[{"lang":"en","value":"CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1419","description":"CWE-1419 Incorrect Initialization of Resource","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T18:12:44.908Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73451 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.7M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.\n</pre>"}],"value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73451 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.7M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train."}],"source":{"advisory":"Security Advisory 0151","defect":["1262274"],"defects":["BUG 1262274"],"discovery":"INTERNAL"},"title":"On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre><p>The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.</p><p>For every SVI check the active ACL(s) applied to it,</p><pre>switch(config)# interface Vlan<i>NNN</i>\nswitch(config-if-Vl<i>NNN</i>)# show active\n</pre><div>&nbsp;</div><p>Then remove the ACL(s) and re-apply them,</p><pre>switch(config-if-Vl<i>NNN</i>)# no ip access-group &lt;acl name&gt; in\nswitch(config-if-Vl<i>NNN</i>)# ip access-group &lt;acl name&gt; in\nswitch(config-if-Vl<i>NNN</i>)# no ipv6 access-group &lt;acl name&gt; in\nswitch(config-if-Vl<i>NNN</i>)# ipv6 access-group &lt;acl name&gt; in\n</pre><div>&nbsp;</div><p>Note: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.</p><p>For more information about Security ACLs see <a href=\"https://www.arista.com/en/um-eos/eos-acls-and-route-maps\" target=\"_blank\" rel=\"noopener noreferrer\">EOS User Manual: ACLs and Route Maps</a>.</p></pre>"}],"value":"The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.\n\n\n\nFor every SVI check the active ACL(s) applied to it,\n\n\n\nswitch(config)# interface VlanNNN\nswitch(config-if-VlNNN)# show active\n\n\n \n\n\n\nThen remove the ACL(s) and re-apply them,\n\n\n\nswitch(config-if-VlNNN)# no ip access-group <acl name> in\nswitch(config-if-VlNNN)# ip access-group <acl name> in\nswitch(config-if-VlNNN)# no ipv6 access-group <acl name> in\nswitch(config-if-VlNNN)# ipv6 access-group <acl name> in\n\n\n \n\n\n\nNote: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.\n\n\n\nFor more information about Security ACLs see  EOS User Manual: ACLs and Route Maps https://www.arista.com/en/um-eos/eos-acls-and-route-maps ."}],"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-73451","datePublished":"2026-09-15T18:12:44.908Z","dateReserved":"2026-08-12T16:42:47.921Z","dateUpdated":"2026-09-15T19:24:42.924Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-15 19:17:38","lastModifiedDate":"2026-09-16 19:08:50","problem_types":["CWE-1419 CWE-1419 Incorrect Initialization of Resource"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-15T19:24:36.704643Z","id":"CVE-2026-73451","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73451","Ordinal":"1","Title":"On affected platforms running Arista EOS with dual switch cards ","CVE":"CVE-2026-73451","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73451","Ordinal":"1","NoteData":"On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","Type":"Description","Title":"On affected platforms running Arista EOS with dual switch cards "}]}}}