Executive brief
Arista EOS network switches can be disrupted by specially crafted packets that cause authenticated Bidirectional Forwarding Detection (BFD) sessions—a critical protocol for network stability—to fail unexpectedly. Because routing protocols rely on BFD to detect network faults and reroute traffic, a successful attack can trigger undesirable network changes, service interruptions, or cascading failures across a datacenter or enterprise network.
Technical details
A specially crafted packet can bypass authentication checks in Arista EOS's BFD implementation (CWE-303: Incorrect Implementation of Authentication Algorithm), causing authenticated BFD sessions to go down. The vulnerability affects BFD sessions configured with any supported authentication mode (Password, Keyed MD5, Meticulous MD5, Keyed SHA1, Meticulous SHA1). An unauthenticated attacker on the network can trigger this without prior authentication, as the vulnerability itself defeats the authentication mechanism. The attack results in BFD session termination, which causes monitoring protocols (BGP, OSPF, etc.) to detect a link failure and reroute traffic, potentially causing network outages or undesired topology changes. Patches are available for affected EOS versions; operators should upgrade to 4.36.2F, 4.35.6M, 4.34.8M, 4.33.9M or later depending on their release train.
Affected products
- Arista EOS 4.36.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.8M and below (4.33.x), and all prior releases
Timeline
- 2026-09-09: disclosed: Arista Security Advisory 0154 initial release
- 2026-09-15: advisory: CVE-2026-73458 published on NVD