---
id: CVE-2026-73450
title: >-
  On affected platforms running Arista EOS with MLAG Dual Primary Detection
  configured, an unauthenticated attacker with access to the Dual Primary
  Detection network segment can send specially crafted packets to interfere with
  the dual-pri…
summary: >-
  On affected platforms running Arista EOS with MLAG Dual Primary Detection
  configured, an unauthenticated attacker with access to the Dual Primary
  Detection network segment can send specially crafted packets to interfere with
  the dual-pri…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H'
cwe:
  - CWE-345
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.1F
  - EOS >= 4.35.0 <= 4.35.5M
  - EOS >= 4.34.0 <= 4.34.7.1M
  - EOS >= 4.33.0 <= 4.33.9M
  - EOS >= 0.0.0 < 4.33.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:07.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73450'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24717-security-advisory-0161
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T17:41:23.594863Z'
epss: 0.0016
epssPercentile: 0.04458
ingestedAt: '2026-09-16T02:48:25.629Z'
---

## Overview

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-primary state. If the MLAG primary switch fails while these packets are present, the secondary switch incorrectly concludes it is in a dual-primary condition and err-disables its interfaces, leading to a traffic interruption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
