{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 151 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151"
      }
    ],
    "title": "Security Advisory 151",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:11Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 151",
      "initial_release_date": "2026-09-17T11:48:11Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:11Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "interim",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "CCS-755-X3-SC hardware platform",
                "product": {
                  "name": "CCS-755-X3-SC hardware platform",
                  "product_id": "CSAFPID-5"
                }
              },
              {
                "category": "product_version",
                "name": "CCS-758-X3-SC hardware platform",
                "product": {
                  "name": "CCS-758-X3-SC hardware platform",
                  "product_id": "CSAFPID-6"
                }
              }
            ],
            "category": "product_family",
            "name": "Hardware Platform"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.5",
                    "product": {
                      "name": "EOS version 4.35.5",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.31.1",
                    "product": {
                      "name": "EOS version 4.31.1",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7",
                    "product": {
                      "name": "EOS version 4.34.7",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.35.5 installed on CCS-758-X3-SC",
          "product_id": "CSAFPID-15"
        },
        "product_reference": "CSAFPID-1",
        "relates_to_product_reference": "CSAFPID-6"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.36.1 installed on CCS-758-X3-SC",
          "product_id": "CSAFPID-16"
        },
        "product_reference": "CSAFPID-3",
        "relates_to_product_reference": "CSAFPID-6"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.35.5 installed on CCS-755-X3-SC",
          "product_id": "CSAFPID-10"
        },
        "product_reference": "CSAFPID-1",
        "relates_to_product_reference": "CSAFPID-5"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.34.7 installed on CCS-758-X3-SC",
          "product_id": "CSAFPID-14"
        },
        "product_reference": "CSAFPID-0",
        "relates_to_product_reference": "CSAFPID-6"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.33.9 installed on CCS-758-X3-SC",
          "product_id": "CSAFPID-13"
        },
        "product_reference": "CSAFPID-2",
        "relates_to_product_reference": "CSAFPID-6"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.36.1 installed on CCS-755-X3-SC",
          "product_id": "CSAFPID-11"
        },
        "product_reference": "CSAFPID-3",
        "relates_to_product_reference": "CSAFPID-5"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.34.7 installed on CCS-755-X3-SC",
          "product_id": "CSAFPID-9"
        },
        "product_reference": "CSAFPID-0",
        "relates_to_product_reference": "CSAFPID-5"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.31.1 installed on CCS-758-X3-SC",
          "product_id": "CSAFPID-12"
        },
        "product_reference": "CSAFPID-4",
        "relates_to_product_reference": "CSAFPID-6"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.33.9 installed on CCS-755-X3-SC",
          "product_id": "CSAFPID-8"
        },
        "product_reference": "CSAFPID-2",
        "relates_to_product_reference": "CSAFPID-5"
      },
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "EOS version 4.31.1 installed on CCS-755-X3-SC",
          "product_id": "CSAFPID-7"
        },
        "product_reference": "CSAFPID-4",
        "relates_to_product_reference": "CSAFPID-5"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73451",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1262274"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73451, the following condition must be met:\n\nSecurity ACL must be configured on SVI in ingress direction, which by default uses a shared ACL identifier. In the example below RACLID = 1 for both switchcards:\n\nIf Security ACL is **not** configured on SVI in ingress direction, there is no exposure to this issue and the message will look something like:",
          "title": "1262274: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-4"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-3"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73451"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.5",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.31.1",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "mitigation",
          "details": "The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.\n\nFor every SVI check the active ACL(s) applied to it,\n\nThen remove the ACL(s) and re-apply them,\n\nNote: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.\n\nFor more information about Security ACLs see [EOS User Manual: ACLs and Route Maps](https://www.arista.com/en/um-eos/eos-acls-and-route-maps)."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-9",
            "CSAFPID-2",
            "CSAFPID-10",
            "CSAFPID-3",
            "CSAFPID-6",
            "CSAFPID-0",
            "CSAFPID-14",
            "CSAFPID-13",
            "CSAFPID-16",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-15",
            "CSAFPID-5",
            "CSAFPID-1",
            "CSAFPID-11",
            "CSAFPID-12"
          ]
        }
      ],
      "title": "CVE-2026-73451"
    }
  ]
}