{"api_version":"1","generated_at":"2026-10-01T16:18:27+00:00","cve":"CVE-2026-73469","urls":{"html":"https://cve.report/CVE-2026-73469","api":"https://cve.report/api/cve/CVE-2026-73469.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73469","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73469"},"summary":{"title":"Security Advisory 0176","description":"When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-09-16 10:16:52","updated_at":"2026-09-16 19:08:50"},"problem_types":["CWE-863","CWE-863 CWE-863 Incorrect Authorization"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","data":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"5.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.8","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","data":{"baseScore":5.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73469","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73469","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.35.0F 4.35.4M custom","platforms":["7050X4 Series","7358X4 Series"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73469 has been fixed in the following releases:\n- 4.36.0F and later releases in the 4.36.x train\n- 4.35.5M and later releases in the 4.35.x train\n\nNo hotfix is available for this issue.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"No mitigation exists for this issue.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"73469","cve":"CVE-2026-73469","epss":"0.002940000","percentile":"0.220430000","score_date":"2026-09-16","updated_at":"2026-09-17 00:07:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-73469","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-16T13:41:28.008891Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-16T13:41:36.781Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["7050X4 Series","7358X4 Series"],"product":"EOS","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"4.35.4M","status":"affected","version":"4.35.0F","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>In order to be vulnerable to CVE-2026-73469, loose mode uRPF must be configured on an interface. This can be checked by showing the interface status, or by checking the current switch config.</p><pre>switch>show ip interface\nEthernet1/1 is up, line protocol is up (connected)\n  Internet address is 192.0.2.1/24\n  ...\n  IP verify unicast source reachable-via any\n  ...</pre><pre>switch>show ipv6 interface\nEthernet1/1 is up, line protocol is up (connected)\n  ...\n  IPv6 verify unicast source reachable-via any\n  ...</pre><pre>switch>show running-config section ip verify\ninterface Ethernet1/1\n   ip verify unicast source reachable-via any</pre><pre>switch>show running-config section ipv6 verify\ninterface Ethernet1/1\n   ipv6 verify unicast source reachable-via any</pre><p>If loose mode uRPF is not configured on an interface, there is no exposure to this issue. In this example, Ethernet1/1 is configured with strict mode uRPF (reachable-via RX), and Ethernet2/1 is not configured with any uRPF — neither are affected:</p><pre>switch>show ip interface\nEthernet1/1 is up, line protocol is up (connected)\n  Internet address is 192.0.2.1/24\n  ...\n  IP verify unicast source reachable-via RX\n  ...\nEthernet2/1 is up, line protocol is up (connected)\n  Internet address is 198.51.100.1/24\n  ...</pre>"}],"value":"In order to be vulnerable to CVE-2026-73469, loose mode uRPF must be configured on an interface. This can be checked by showing the interface status, or by checking the current switch config.\n\n  switch>show ip interface\n  Ethernet1/1 is up, line protocol is up (connected)\n    Internet address is 192.0.2.1/24\n    ...\n    IP verify unicast source reachable-via any\n    ...\n\n  switch>show ipv6 interface\n  Ethernet1/1 is up, line protocol is up (connected)\n    ...\n    IPv6 verify unicast source reachable-via any\n    ...\n\n  switch>show running-config section ip verify\n  interface Ethernet1/1\n     ip verify unicast source reachable-via any\n\n  switch>show running-config section ipv6 verify\n  interface Ethernet1/1\n     ipv6 verify unicast source reachable-via any\n\nIf loose mode uRPF is not configured on an interface, there is no exposure to this issue. In this example, Ethernet1/1 is configured with strict mode uRPF (reachable-via RX), and Ethernet2/1 is not configured with any uRPF — neither are affected:\n\n  switch>show ip interface\n  Ethernet1/1 is up, line protocol is up (connected)\n    Internet address is 192.0.2.1/24\n    ...\n    IP verify unicast source reachable-via RX\n    ...\n  Ethernet2/1 is up, line protocol is up (connected)\n    Internet address is 198.51.100.1/24\n    ..."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.</p><p>This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.</p>"}],"value":"When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks."}],"metrics":[{"cvssV3_1":{"baseScore":5.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"baseScore":6.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T10:13:40.801Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"name":"Security Advisory 0176","tags":["vendor-advisory"],"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.</p><p>CVE-2026-73469 has been fixed in the following releases:</p><ul><li>4.36.0F and later releases in the 4.36.x train</li><li>4.35.5M and later releases in the 4.35.x train</li></ul><p>No hotfix is available for this issue.</p>"}],"value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73469 has been fixed in the following releases:\n- 4.36.0F and later releases in the 4.36.x train\n- 4.35.5M and later releases in the 4.35.x train\n\nNo hotfix is available for this issue."}],"source":{"advisory":"Security Advisory 0176","defects":["BUG 1353206"],"discovery":"INTERNAL"},"title":"Security Advisory 0176","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>No mitigation exists for this issue.</p>"}],"value":"No mitigation exists for this issue."}]}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-73469","datePublished":"2026-09-16T09:55:14.065Z","dateReserved":"2026-08-12T16:47:18.121Z","dateUpdated":"2026-09-16T13:41:36.781Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 10:16:52","lastModifiedDate":"2026-09-16 19:08:50","problem_types":["CWE-863","CWE-863 CWE-863 Incorrect Authorization"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-16T13:41:28.008891Z","id":"CVE-2026-73469","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73469","Ordinal":"1","Title":"Security Advisory 0176","CVE":"CVE-2026-73469","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73469","Ordinal":"1","NoteData":"When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.\n\nThis issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.","Type":"Description","Title":"Security Advisory 0176"}]}}}