CVE-2026-73435

Summary

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0F <= 4.36.1Faffected
Arista NetworksEOS4.35.0F <= 4.35.5Maffected
Arista NetworksEOS4.34.0F <= 4.34.7Maffected
Arista NetworksEOS4.33.0F <= 4.33.9Maffected
Arista NetworksEOS1.0.0 < 4.33.0Faffected

Weaknesses

  • CWE-345: CWE-345 Insufficient Verification of Data Authenticity

Workarounds

No mitigation is available for CVE-2026-73435.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References