CVE-2026-73455: Security Advisory 0173
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.9M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.7M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.1F - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Patch Security Advisory 0173
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Affected platforms are those running Arista EOS with OSPFv3 configured. Systems without OSPFv3 configured are not identified as affected by the advisory description.
What does an attacker need to do to trigger the problem?
An attacker needs to send a specially crafted packet to the affected system. The supplied vector indicates network-based exploitation with no privileges or user interaction required.
What is the expected impact of successful exploitation?
Successful exploitation can cause the OSPFv3 agent to restart unexpectedly, creating an availability impact. The provided impact metrics indicate no confidentiality or integrity impact.