Junglewise Threat Intelligence

CVE-2026-73436: Arista EOS OSPFv2 segment routing denial of service

CVE-2026-73436 · Severity: medium · CVSS 6.5 · Published 2026-09-16

Executive brief

Arista EOS, a widely-used routing and switching operating system, contains a vulnerability in its OSPF (Open Shortest Path First) routing protocol implementation. An attacker on the same network segment can send a specially crafted packet that causes the OSPF process to restart unexpectedly, disrupting routing convergence and potentially causing network outages. This impacts network availability on affected Arista platforms running the vulnerable EOS versions.

Technical details

CVE-2026-73436 is a denial-of-service vulnerability in Arista EOS affecting OSPFv2 with segment routing enabled. The issue is triggered by improper validation of incoming OSPFv2 packets (CWE-1284: Improper Validation of Specified Quantity in Input; CWE-125: Out-of-bounds Read). An adjacent OSPF neighbor can send a maliciously crafted OSPFv2 packet that causes the OSPF daemon to crash and restart. The attack requires network adjacency (AV:A) and no authentication bypass, as an established OSPF neighbor relationship is sufficient to inject packets. The vulnerability affects EOS versions 4.36.1F and below in the 4.36.x train, 4.35.5M and below in 4.35.x, 4.34.7.1M and below in 4.34.x, 4.33.9M and below in 4.33.x, and all prior releases. Patches are available via Arista advisory 0171.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x train); 4.35.5M and below (4.35.x train); 4.34.7.1M and below (4.34.x train); 4.33.9M and below (4.33.x train); all prior releases

Timeline

  • 2026-09-09: disclosed
  • 2026-09-16: advisory: Published on NVD

References

Related threats