Junglewise Threat Intelligence

CVE-2026-73446: Arista EOS IS-IS Hello PDU denial of service

CVE-2026-73446 · Severity: high · CVSS 7.4 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches running the IS-IS routing protocol can be disrupted by an attacker on the same local network sending specially crafted protocol messages. An attacker can tear down established routing connections, causing network traffic to be lost and making portions of the network unreachable. This attack requires no authentication and can result in significant service disruptions.

Technical details

CVE-2026-73446 is an unauthenticated denial of service vulnerability affecting Arista EOS running IS-IS (Intermediate System to Intermediate System) on broadcast interfaces. An attacker in the same Layer 2 domain can send a crafted IS-IS Hello PDU that triggers improper protocol state handling (CWE-696: Incorrect Behavior Order), causing the device to tear down established IS-IS adjacencies. The vulnerability bypasses RFC 5304/5310 MD5/SHA authentication mechanisms. The attack vector is adjacent-network (Layer 2 adjacent), requires no user interaction or authentication, and impacts network availability by disrupting IP reachability for prefixes advertised through the torn adjacency. Patches are available; affected versions include EOS 4.36.1F and below (4.36.x train), 4.35.5M and below (4.35.x train), 4.34.7.1M and below (4.34.x train), 4.33.9M and below (4.33.x train), and all 4.32.x/4.31.x releases.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7.1M and below (4.34.x), 4.33.9M and below (4.33.x), all 4.31.x and 4.32.x

Timeline

  • 2026-09-09: advisory: Arista Security Advisory 0160 released
  • 2026-09-16: disclosed: CVE-2026-73446 published on NVD

References

Related threats