---
id: CVE-2026-77190
title: >-
  On affected platforms running Arista EOS, an unauthenticated attacker who is
  network-adjacent to the switch and able to connect to a device with PIM Sparse
  Mode and MLAG configured, can send malformed messages that cause the Pimsm
  agent …
summary: >-
  On affected platforms running Arista EOS, an unauthenticated attacker who is
  network-adjacent to the switch and able to connect to a device with PIM Sparse
  Mode and MLAG configured, can send malformed messages that cause the Pimsm
  agent …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0F <= 4.36.1F
  - EOS >= 4.35.0F <= 4.35.5M
  - EOS >= 4.34.2F <= 4.34.7M
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:08:50.420'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77190'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24733-security-advisory-0177
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T13:26:18.181290Z'
ingestedAt: '2026-09-16T10:53:53.923Z'
epss: 0.00281
epssPercentile: 0.18421
---

## Overview

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent to terminate unexpectedly. The Pimsm agent is automatically restarted, but repeated attacks can cause the agent to restart continuously, resulting in a sustained denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
