Junglewise Threat Intelligence

CVE-2026-73438: Arista EOS OSPFv3 agent denial of service

CVE-2026-73438 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Executive brief

Arista EOS network switches running OSPFv3 can be crashed by an attacker on the same local network who sends specially crafted packets. The crash terminates the OSPFv3 routing agent, disrupting network routing until the agent restarts. This affects organizations using Arista switches as core network infrastructure.

Technical details

This vulnerability is a reachable assertion (CWE-617) in the Ospf3 agent on Arista EOS platforms. An unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted series of packets that trigger an unexpected agent restart. The attack requires network access to the OSPFv3 segment (adjacent network vector) and no authentication. Successful exploitation causes loss of all OSPFv3 adjacencies on the device and may disrupt routing across the broader OSPF domain. OSPFv3 authentication/encryption can mitigate this vulnerability by rejecting unauthenticated packets before they reach the vulnerable code.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.9M and below (4.33.x), all prior releases

Timeline

  • 2026-09-09: disclosed: Arista security advisory released
  • 2026-09-22: other: Advisory revision 1.1 with CSAF JSON file added

References

Related threats