GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfaces

CVSS 7.0CVE-2026-73450Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker on the dual-primary detection segment can inject packets that corrupt MLAG dual-primary state. If the MLAG primary then fails, the secondary wrongly concludes both peers are primary and err-disables its interfaces - so the failover that was supposed to keep the rack online instead takes the whole MLAG pair down. For a GPU fleet this is a rack-wide loss of north-south and storage connectivity, and err-disabled ports need operator action to recover, not just a link flap. It requires the attacker to be present at the moment of a primary failure, which is why the vector is rated attack-requirements-present.

Who can reach it

Unauthenticated attacker with packet access to the MLAG dual-primary detection network segment. This is normally a management or peer-link segment, so exposure depends on whether that segment is reachable from tenant or general-purpose networks.

What to do

Upgrade to the fixed EOS release or apply the hotfix from Arista security advisory 0161; the record does not name a fixed version, so take it from the advisory. Until then, restrict the dual-primary detection segment to the MLAG peers themselves. Upgrading an MLAG pair is a two-stage switch maintenance window and each stage removes one side of the redundancy.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.