CVE-2026-73459

Summary

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.36.0 <= 4.36.1Faffected

Weaknesses

  • CWE-354: CWE-354: Improper Validation of Integrity Check Value

Workarounds

No workaround is available for this issue.

References