endoflife.ai
Arista EOS EOS 4.31.x EOS Edge Device List EOL Checker

Arista EOS End of Life: 4.31.x Support Ends October 13, 2026 — What 4.30 to 4.36 Owners Should Know

By Scott Bissett  ·  Published: October 10, 2026  ·  Reference guide  ·  Dates and policy wording read from Arista's EOS Life Cycle Policy page and Security Advisory 0137 on the day of publication.

Arista EOS 4.31.x reaches its End of Support Date on October 13, 2026, 36 months after its initial release on October 13, 2023. Both dates are from the release support matrix on Arista's EOS Life Cycle Policy page, which already lists the train in its Support Only phase: TAC support continues, but a bug fix means moving to a newer train. After the End of Support Date, 4.31.x joins 4.30.x and the older trains that Arista says have reached End of Support. The train's live status and EOL Risk Score are on its page.

An upgrade is the answer to end of support, not to the exploited flaw. CVE-2026-7473, the one Arista EOS entry in CISA's Known Exploited Vulnerabilities catalog, affects every EOS train in Arista's advisory, 4.36.x and newer included, and Arista says no software upgrade path is planned. Moving off 4.31.x restores a path to bug fixes; the exploited flaw is handled by configuration on the 7020R, 7280R/R2 and 7500R/R2 series whatever train they run. Details below.
Quick answer: The Arista EOS 4.31.x end-of-life (EOL) date is October 13, 2026. Every Arista EOS version's release and end-of-support date is on the Arista EOS lifecycle page.

Arista's EOS life cycle policy, in plain words

Arista states the rule in one sentence on the policy page: "Arista will support each major EOS software release for up to 36 months from the date of initial posting for a particular train." A train is a major release line such as 4.31.x; the individual builds inside it carry a letter that tells you which phase the train is in. In Arista's words: “Each EOS software release is identified with either the letter "F" indicating that the release contains new Functionality or "M", denoting that the release is in the Maintenance phase. An M release only receives incremental fixes and no new functionality is added.” The policy page names no other kind of train: there are F builds, M builds and the three phases below.

Phase in Arista's policyWhat Arista says it includesWhat it means for a switch on that train
New Feature PhaseReleases “identified with the letter "F" indicating that the release contains new feature/functionality”; “TAC support available”New features arrive in F builds. The train is young; Arista's diagram, which it marks as a generic example, shows the New Feature and Maintenance phases together lasting 30 months
Maintenance PhaseReleases “identified with the letter "M" for maintenance phase”; “An M release only receives incremental fixes and no new functionality is added”; “TAC support available”Bug fixes keep coming as M builds of the same train. Most of a train's life is spent here
Support Only Phase“Ongoing TAC support”; “Software upgrade required for bug fixes”You can still open a case, but a bug found now is fixed in a later train. The same generic diagram shows this phase as the final 6 months of the 36. 4.31.x is here until October 13, 2026
End of SupportThe state of the trains below the line in Arista's table: "Arista EOS 4.30 and earlier releases have reached End of Support."The 36 months are over. Arista's policy page lists no support for the train; migration help is a sales conversation

Arista's table prints two dates per train, the Initial Release Date and the End of Support Date, which it labels "+36 months from initial release". It does not print the day a train leaves Maintenance for Support Only, so the Arista EOS page and this guide serve the release and end-of-support dates only; the phase column in Arista's table is a snapshot, and Arista notes that "Future dates are for general planning purposes and are subject to change".

What changes for 4.31.x on October 13, 2026

Less than you might expect on the day, and more over the months after it. Arista's table already shows 4.31.x in the Support Only phase, so the train has not had new M builds for some time; a bug found in 4.31.x today is already answered with "upgrade". What October 13, 2026 marks is the end of the 36 months of support Arista promises for the train, including the TAC support the Support Only phase still carries. From then on, 4.31.x belongs with the releases Arista's page describes as having "reached End of Support", the line it draws today under 4.30.x (End of Support April 14, 2026). A switch that keeps running 4.31.x keeps forwarding packets; what it loses is a vendor that will look at its software.

Two things the date does not do. It does not change hardware support, which Arista tracks separately on its end-of-sale notices, and it does not change the exploited-vulnerability picture, because CVE-2026-7473 is not fixed in any train.

Running Arista EOS past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Arista EOS is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Every EOS train in Arista's table, and where it stands

TrainInitial releaseEnd of Support (EOL)Status today
EOS 4.36.xApril 8, 2026April 8, 2029Supported
EOS 4.35.xOctober 6, 2025October 6, 2028Supported
EOS 4.34.xApril 25, 2025April 25, 2028Supported
EOS 4.33.xOctober 10, 2024October 10, 2027Approaching
EOS 4.32.xApril 9, 2024April 9, 2027Approaching
EOS 4.31.xOctober 13, 2023October 13, 2026Approaching
EOS 4.30.xApril 14, 2023April 14, 2026EOL
EOS 4.29.xOctober 31, 2022October 31, 2025EOL
EOS 4.28.xApril 18, 2022April 18, 2025EOL
EOS 4.27.xSeptember 27, 2021September 27, 2024EOL
EOS 4.26.xApril 15, 2021April 15, 2024EOL

Every date is Arista's, copied from the Initial Release Date and End of Support Date columns of the matrix on the policy page; the status column is computed from those dates at every build of this site. Arista's phase column, as the table currently stands, has 4.36.x in the New Feature Phase, 4.32.x to 4.35.x in the Maintenance Phase, 4.31.x in Support Only and 4.30.x and older at End of Support. Trains older than 4.26.x are not in Arista's table.

Hardware exceptions. Arista's table carries a Platform Specific Exceptions column. For 4.33.x it keeps the 7280R/7280R2, 7500R/7500R2 and 7020R series in the Maintenance Phase beyond the train's general date, and for 4.28.x it did the same for the 7050X/7050X2, 7300X and 7010T series; Arista's footnote adds that the Support Only phase is "extended till the end of life of respective hardware" as listed on its end-of-sale page. The dates in this table are for each train in general; the per-platform exception dates are on the Arista EOS page.

The pattern is regular: Arista has posted a new train roughly every six months, one each spring and one each autumn, and every train's End of Support Date in the table is exactly 36 months after its initial release. A switch that moves train every two years never spends time in Support Only; one that moves every three arrives there every time.

The exploited flaw an upgrade does not fix

CISA's Known Exploited Vulnerabilities catalog files Arista EOS under the vendor "Arista" and the product "Extensible Operating System", and holds one entry for it. CISA's fields, quoted as the catalog prints them:

CISA fieldCatalog value
cveIDCVE-2026-7473
vulnerabilityNameArista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
dateAddedJune 9, 2026
dueDateJune 23, 2026 (the federal remediation deadline)
shortDescription"Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP."
requiredAction"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable."
knownRansomwareCampaignUseUnknown
cwesCWE-1023

Arista's own account is Security Advisory 0137. It says "This issue has been reported as being exploited in the wild", and its affected-software list is every train: "All releases in the 4.36.x train" down to "All releases in the 4.30.x train", then "All releases in trains older than 4.30.x" and "All releases in trains newer than 4.36.x". The affected platforms are the 7020R Series, 7280R/R2 Series and 7500R/R2 Series, with "Limited exposure (IP-in-IPv6 and GUEv6)" on the 7280R3, 7500R3 and 7800R3 Series; the advisory's long list of unaffected products includes the 7050X and 7060X data-centre families, CloudEOS and the VeloCloud line. A device is exposed only when it is "configured as a tunnel endpoint with a decapsulation IP", such as a VXLAN VTEP, a GRE tunnel endpoint or an ip decap-group: it then "will also incorrectly accept and decapsulate other tunnel protocols destined to the same IP address".

Under Resolution the advisory says: "No software upgrade path is planned to address this issue due to the risk of breaking existing configuration on deployments. The recommended resolution of this issue is to follow the appropriate mitigation instructions detailed above." Under Hotfix: "No hotfix is available for these issues." The mitigations are access lists, applied either on upstream devices or on the decapsulating switch itself, that permit only the tunnel protocol a decapsulation address is meant to receive and deny the rest. That is why the end-of-support question and the exploited-flaw question are separate for Arista EOS: moving from 4.31.x to a supported train is right for every other reason, and does nothing for this one.

The two other Arista entries in CISA's catalog, CVE-2026-16812 and CVE-2026-93952, are in VeloCloud Orchestrator, a different product with its own end-of-support story. Arista EOS is on our EOS Edge Device List because the 7280R and 7500R routing families sit at peering and internet edges, which is exactly where CVE-2026-7473 lands.

What to do

  1. On 4.31.x: pick a train whose End of Support Date is years out. 4.34.x (End of Support April 25, 2028) and 4.35.x (October 6, 2028) are in Arista's Maintenance Phase; 4.36.x (April 8, 2029) is still in its New Feature Phase, so its M builds are ahead of it. 4.32.x buys only until April 9, 2027.
  2. Check the platform before the train. Arista's release notes list which hardware each train supports, and the table's platform exceptions show that some older R-series platforms are deliberately kept on older trains. Confirm the target train for your exact model and the upgrade path Arista documents for it.
  3. On 4.30.x or older: Arista's page already counts you among the releases that have reached End of Support. There is no Support Only phase left to lean on; the move is overdue.
  4. On the 7020R, 7280R/R2 or 7500R/R2 series, any train: run the three checks in Advisory 0137 (the VXLAN interface, tunnel interface and ip decap-group show commands). If any shows a decapsulation address, apply the access lists the advisory gives, and permit the management and routing protocols that address also serves before the deny line.
  5. Watch the dates, not the phase labels. Arista's table prints the End of Support Date for every train and nothing for the Maintenance to Support Only hand-off, and it says future dates are for planning purposes. The Arista EOS page re-reads the table and shows each train's live status.

Frequently Asked Questions

When is Arista EOS 4.31 end of life?

Arista's EOS Life Cycle Policy table gives Arista EOS 4.31.x an End of Support Date of October 13, 2026, 36 months after its initial release on October 13, 2023. Arista's table already lists the train in the Support Only phase: TAC support continues until the End of Support Date, but a software upgrade is required for bug fixes.

What does Arista's Support Only phase mean?

Arista describes the Support Only phase with two lines: ongoing TAC support, and software upgrade required for bug fixes. A switch on a Support Only train can still open a case with Arista's TAC, but a fix for a bug found in that train is delivered in a later train, not as a new 4.31 build.

Which Arista EOS trains are still within their support window?

Arista's table lists 4.32.x through 4.36.x inside their 36-month windows: 4.32.x reaches End of Support on April 9, 2027 and 4.36.x, the newest train in the table, on April 8, 2029. Below the table Arista states that Arista EOS 4.30 and earlier releases have reached End of Support.

Does upgrading EOS fix CVE-2026-7473?

No. Arista's Security Advisory 0137 lists every EOS train, including trains newer than 4.36.x, as affected, and says no software upgrade path is planned to address this issue. CISA added CVE-2026-7473 to its Known Exploited Vulnerabilities catalog on June 9, 2026. The mitigation is configuration: access lists that admit only the tunnel protocol a decapsulation address is meant to receive.

Related

© 2026 endoflife.ai · How we verify our dates · API · About