Junglewise Threat Intelligence

CVE-2026-73455: Arista EOS OSPFv3 denial of service via crafted packet

CVE-2026-73455 · Severity: high · CVSS 7.5 · Published 2026-09-16

Executive brief

Arista EOS is a network operating system used on Arista switches and routers. A specially crafted network packet can cause the OSPFv3 routing protocol agent to crash and restart unexpectedly, disrupting dynamic routing and potentially causing traffic blackholes. This issue requires OSPFv3 to be enabled and affects multiple Arista switch platforms.

Technical details

This vulnerability is an improper handling of length parameter inconsistency (CWE-130) in the OSPFv3 agent on Arista EOS. A remote, unauthenticated attacker can send a specially crafted OSPFv3 packet over the network to trigger an unhandled exception or memory corruption in the OSPFv3 daemon, causing it to crash with a SIGQUIT signal. Exploitation requires OSPFv3 to be configured and at least one active neighbor relationship to be present. The crash can be detected via system logs showing process termination and restart of the Ospf3 daemon. Mitigation is available through enabling OSPFv3 authentication (IPSec ESP encryption with authentication) on all OSPFv3 interfaces to reject unauthenticated packets before processing.

Affected products

  • Arista EOS 4.36.0.1F and below (4.36.x train), 4.35.4M and below (4.35.x train), 4.34.6M and below (4.34.x train), 4.33.8M and below (4.33.x train), and all prior releases

Timeline

  • 2026-09-09: advisory: Arista Security Advisory 0173 published (initial release)
  • 2026-09-16: disclosed: Vulnerability disclosed publicly via NVD

References

Related threats