Junglewise Threat Intelligence

CVE-2026-73460: Arista EOS IS-IS graceful restart denial of service

CVE-2026-73460 · Severity: medium · CVSS 6.1 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches running IS-IS with graceful restart enabled can be disrupted by an attacker on the same network segment. An attacker can send a specially crafted packet that prematurely terminates the graceful restart procedure, causing traffic loss after a device restart and potentially disrupting network connectivity across the affected routing domain.

Technical details

This vulnerability is an incorrect authorization flaw (CWE-863) in the IS-IS graceful restart mechanism on Arista EOS. An unauthenticated attacker on the same Layer 2 domain can inject a malformed IS-IS Link State PDU (LSP) packet to trigger improper handling of the graceful restart procedure. The attack requires IS-IS graceful restart to be configured and does not require authentication; the attacker must be network-adjacent (same broadcast domain). Successful exploitation causes the graceful restart process to terminate prematurely, resulting in traffic loss following a device restart. No user interaction is required. Patches are available in EOS 4.36.2F and later releases.

Affected products

  • Arista EOS 4.36.1F and below

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0160 initial release
  • 2026-09-16: advisory: CVE-2026-73460 published to NVD

References

Related threats