CVE-2026-73446
7.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Summary
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Arista Networks | EOS | 4.36.0 <= 4.36.1F | affected |
| Arista Networks | EOS | 4.35.0 <= 4.35.5M | affected |
| Arista Networks | EOS | 4.34.0 <= 4.34.7.1M | affected |
| Arista Networks | EOS | 4.33.0 <= 4.33.9M | affected |
| Arista Networks | EOS | 4.32.0 < 4.33.0F | affected |
| Arista Networks | EOS | 4.31.0 < 4.32.0F | affected |
Weaknesses
- CWE-696: CWE-696: Incorrect Behavior Order
Workarounds
No workaround is available for this issue.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.