在运行 Arista EOS 的受影响平台上,若配置了双交换引擎卡,并在共享模式下的交换虚拟接口(SVI)上启入了入方向安全访问控制列表(Security ACL),当重启备用交换引擎卡的前向代理(forwarding agent)或插入备用交换引擎卡时,可能导致共享 SVI 上的安全 ACL 失效。这可能会引起数据包放行/拒绝行为异常。 此问题由 Arista 内部发现,该公司目前未察觉客户网络中有任何恶意利用该漏洞的情况。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | EOS | 4.36.0≤ 4.36.0.1F |
affected |
4.35.0≤ 4.35.4M |
affected | ||
4.34.0≤ 4.34.6M |
affected | ||
4.33.0≤ 4.33.8M |
affected | ||
4.32.0≤ 4.32.11M |
affected | ||
4.31.1F≤ 4.31.10M |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Arista Networks | EOS | 4.36.0 ~ 4.36.0.1F | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73437 | 9.6 CRITICAL | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) r |
| CVE-2026-73458 | 8.2 HIGH | On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detec |
| CVE-2026-73459 | 7.4 HIGH | Security Advisory 0160 |
| CVE-2026-73446 | 7.4 HIGH | Security Advisory 0160 |
| CVE-2026-19655 | 6.5 MEDIUM | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) r |
| CVE-2026-73466 | 6.3 MEDIUM | On affected platforms running Arista EOS, under certain circumstances plaintext user passw |
| CVE-2026-73465 | 6.3 MEDIUM | On affected platforms running Arista EOS, under certain circumstances plaintext private ke |
| CVE-2026-73467 | 6.3 MEDIUM | On affected platforms running Arista EOS, under certain circumstances plaintext shared sec |
| CVE-2026-73460 | 6.1 MEDIUM | Security Advisory 0160 |
| CVE-2026-19641 | 5.3 MEDIUM | On affected platforms running Arista EOS with password authentication configured, a specia |
| CVE-2026-73444 | 4.7 MEDIUM | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) auth |
No comments yet