CVE-2026-73435: Security Advisory 0171
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.10M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.7.1M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Patch Security Advisory 0171
Event History
Frequently Asked Questions
Which deployments should be prioritized for assessment?
Prioritize affected Arista EOS platforms that run OSPFv2 on broadcast segments and have OSPFv2 authentication configured. Platforms without OSPFv2 configured are not identified as affected by the available information.
Does OSPFv2 authentication prevent exploitation?
No. The issue is described as exploitable when OSPFv2 authentication is configured.
What access would an attacker need?
An unauthenticated attacker must be on the same broadcast segment as the targeted OSPFv2 deployment and able to send a specially crafted OSPFv2 packet.
How far can the operational impact spread?
The immediate effects are adjacency flapping and packet loss, but resulting routing disruption can affect the broader OSPF domain.