CVE-2026-73451: CWE-1419 Incorrect Initialization of Resource in Arista Networks EOS
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
AI Analysis
Technical Summary
This vulnerability involves incorrect initialization of resources (CWE-1419) in Arista EOS when running on affected platforms with dual switch cards and ingress Security ACLs configured on shared-mode SVIs. Specifically, restarting the secondary switchcard forwarding agent or inserting the secondary switchcard can cause the security ACLs on shared SVIs to cease functioning properly, resulting in incorrect packet filtering behavior. The vulnerability was internally discovered by Arista and has not been reported exploited in the wild.
Potential Impact
The impact is limited to the potential failure of security ACLs on shared SVIs to enforce intended packet filtering rules after certain operations on the secondary switchcard. This may allow packets that should be denied or block packets that should be permitted, leading to reduced security enforcement on affected network segments. There is no reported confidentiality or availability impact beyond this ACL malfunction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor Arista's advisories for updates. Until a fix is available, avoid restarting or inserting the secondary switchcard on affected platforms with ingress Security ACLs configured on shared SVIs in shared mode to prevent ACL malfunction.
CVE-2026-73451: CWE-1419 Incorrect Initialization of Resource in Arista Networks EOS
Description
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
CVSS v3.1
Score 4.8medium
Affected software
Arista Networks
EOS
pkg:github/arista-networks/eosRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves incorrect initialization of resources (CWE-1419) in Arista EOS when running on affected platforms with dual switch cards and ingress Security ACLs configured on shared-mode SVIs. Specifically, restarting the secondary switchcard forwarding agent or inserting the secondary switchcard can cause the security ACLs on shared SVIs to cease functioning properly, resulting in incorrect packet filtering behavior. The vulnerability was internally discovered by Arista and has not been reported exploited in the wild.
Potential Impact
The impact is limited to the potential failure of security ACLs on shared SVIs to enforce intended packet filtering rules after certain operations on the secondary switchcard. This may allow packets that should be denied or block packets that should be permitted, leading to reduced security enforcement on affected network segments. There is no reported confidentiality or availability impact beyond this ACL malfunction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor Arista's advisories for updates. Until a fix is available, avoid restarting or inserting the secondary switchcard on affected platforms with ingress Security ACLs configured on shared SVIs in shared mode to prevent ACL malfunction.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Arista
- Date Reserved
- 2026-08-12T16:42:47.921Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa98f2d55bf5e2cf53845cf
Added to database: 09/15/2026, 18:32:13 UTC
Last enriched: 09/15/2026, 18:47:01 UTC
Last updated: 09/16/2026, 03:07:25 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.