Junglewise Threat Intelligence

CVE-2026-73459: Arista EOS IS-IS LSP improper validation in link-state database

CVE-2026-73459 · Severity: high · CVSS 7.4 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS is a network operating system used to manage enterprise switches and routers. An unauthenticated attacker on the same network segment can send a malformed routing update that causes legitimate network routing information to be incorrectly deleted, leading to traffic loss and service interruption.

Technical details

This vulnerability exists in the IS-IS (Intermediate System to Intermediate System) routing protocol implementation in Arista EOS. The flaw involves improper validation of integrity check values (CWE-354) in Link State PDUs (LSPs), allowing an unauthenticated attacker on the same Layer 2 domain to inject a specially crafted LSP that triggers incorrect purging of legitimate LSPs from the link-state database. The attack requires network adjacency but no authentication or user interaction. An attacker can exploit this to cause traffic loss by disrupting the routing database that IS-IS relies upon, potentially bypassing RFC 5304/5310 MD5/SHA authentication protections. Patches are available for affected EOS versions.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x train)

Timeline

  • 2026-09-16: disclosed
  • 2026-09-09: advisory: Arista Security Advisory 0160

References

Related threats