{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 176 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24732-security-advisory-0176"
      }
    ],
    "title": "Security Advisory 176",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:23Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 176",
      "initial_release_date": "2026-09-17T11:48:23Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:23Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.0",
                    "product": {
                      "name": "EOS version 4.36.0",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.5",
                    "product": {
                      "name": "EOS version 4.35.5",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.2",
                    "product": {
                      "name": "EOS version 4.35.2",
                      "product_id": "CSAFPID-2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73469",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1353206"
      },
      "notes": [
        {
          "category": "description",
          "text": "When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain traffic may not be subjected to the intended verification drop. Consequently, traffic that should be dropped based on these routes could still be processed and forwarded by the device.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73469, loose mode uRPF must be configured on an interface. This can be checked by showing the interface status, or by checking the current switch config.\n\n \n\nIf loose mode uRPF is not configured on an interface, there is no exposure to this issue. In this example, Ethernet1/1 is configured with strict mode uRPF, and Ethernet2/1 is not configured with any uRPF. Therefore neither are affected.",
          "title": "1353206: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73469"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.5",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.0",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.35.2",
          "product_ids": [
            "CSAFPID-2"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-1",
            "CSAFPID-0",
            "CSAFPID-2"
          ]
        }
      ],
      "title": "CVE-2026-73469"
    }
  ]
}