Junglewise Threat Intelligence

CVE-2026-73759: Arista AOS-CX denial of service via crafted packets

CVE-2026-73759 · Severity: medium · CVSS 6.5 · Published 2026-09-01

Vendors: Arista.

Executive brief

AOS-CX is a network operating system used in enterprise switches and routers. An unauthenticated attacker on the network can crash or disable affected devices by sending specially crafted packets, disrupting network connectivity and operations without requiring any credentials or user interaction.

Technical details

This vulnerability allows an unauthenticated remote attacker to trigger a denial-of-service condition in AOS-CX by sending specially crafted network packets to an affected device. The vulnerability does not require authentication or user interaction, as it can be exploited directly over the network. Successful exploitation results in disruption of normal operation on the affected network device, causing service unavailability. The attack is triggered by malformed or specially crafted packet structures that the operating system fails to handle properly. A fix or patch is expected to be available from the vendor to address this issue.

Affected products

  • Arista AOS-CX

Timeline

  • 2026-09-01: disclosed

References