CVE-2026-73435
8.2
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Summary
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | EOS | 4.36.0F <= 4.36.1F | affected |
| Arista Networks | EOS | 4.35.0F <= 4.35.5M | affected |
| Arista Networks | EOS | 4.34.0F <= 4.34.7M | affected |
| Arista Networks | EOS | 4.33.0F <= 4.33.9M | affected |
| Arista Networks | EOS | 1.0.0 < 4.33.0F | affected |
Weaknesses
- CWE-345: CWE-345 Insufficient Verification of Data Authenticity
Workarounds
No mitigation is available for CVE-2026-73435.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.