Executive brief
Arista EOS network switches running IS-IS with graceful restart enabled can be disrupted by an attacker on the same network segment. An attacker can send a specially crafted packet that prematurely terminates the graceful restart procedure, causing traffic loss after a device restart and potentially disrupting network connectivity across the affected routing domain.
Technical details
This vulnerability is an incorrect authorization flaw (CWE-863) in the IS-IS graceful restart mechanism on Arista EOS. An unauthenticated attacker on the same Layer 2 domain can inject a malformed IS-IS Link State PDU (LSP) packet to trigger improper handling of the graceful restart procedure. The attack requires IS-IS graceful restart to be configured and does not require authentication; the attacker must be network-adjacent (same broadcast domain). Successful exploitation causes the graceful restart process to terminate prematurely, resulting in traffic loss following a device restart. No user interaction is required. Patches are available in EOS 4.36.2F and later releases.
Affected products
- Arista EOS 4.36.1F and below
Timeline
- 2026-09-09: disclosed: Arista Security Advisory 0160 initial release
- 2026-09-16: advisory: CVE-2026-73460 published to NVD