Description
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Published: 2026-09-16
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service to routing infrastructure
Action: Patch
AI Analysis

Impact

On Arista EOS systems with Open Shortest Path First (OSPFv2) and authentication enabled, an attacker can send a specially crafted OSPFv2 packet from an unauthenticated host on the same broadcast segment. The packet triggers adjacency flapping and causes packet loss across the OSPF domain, which destabilizes routing and leads to denial of service for the network relying on OSPF for routing.

Affected Systems

Arista Networks EOS firmware in the 4.36.x (fixed starting 4.36.2F), 4.35.x (fixed 4.35.6M), 4.34.x (fixed 4.34.7.1M), and 4.33.x (fixed 4.33.10M) release trains is affected. Hotfixes are available for 4.36.1F, 4.35.5M, 4.34.7M, and 4.33.9M. The issue only manifests on platforms running OSPFv2 with authentication configured.

Risk and Exploitability

The CVSS score of 7.0 denotes moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation; the vulnerability is not listed in CISA KEV. It is locally exploitable by an attacker who can inject OSPF packets on the same broadcast segment. Successful exploitation can lead to OSPF adjacency flapping and consequent packet loss, effectively causing denial‑of‑service for networks relying on OSPF for routing.

Generated by OpenCVE AI on September 18, 2026 at 12:56 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73435 has been fixed in the following releases: - 4.36.2F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.33.10M and later releases in the 4.33.x train A hotfix is available for the following releases: 4.36.1F, 4.35.5M, 4.34.7M, 4.33.9M. URL: https://www.arista.com/support/advisories-notices/sa-download/?sa171-SecurityAdvisory171_CVE-2026-73435.swix SWIX hash (SHA512): 4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7 Note: Installing/uninstalling the SWIX will cause the Ospf process to restart.


Vendor Workaround

No mitigation is available for CVE-2026-73435.


OpenCVE Recommended Actions

  • Upgrade to a remediated firmware version—4.36.2F or later, 4.35.6M or later, 4.34.7.1M or later, or 4.33.10M or later—or apply the appropriate SWIX hotfix for the current train. The SWIX installation restarts the OSPF process, so schedule it during a planned maintenance window.
  • If an immediate firmware upgrade is not possible, isolate the affected OSPF interfaces to a separate broadcast domain or block untrusted OSPFv2 packets until the patch can be deployed.
  • If upgrading is not immediately possible, block or filter OSPFv2 packets from untrusted hosts on the broadcast segment using access control lists or interface‑level security settings to mitigate the risk until a fix is deployed.

Generated by OpenCVE AI on September 18, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Title Security Advisory 0171
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T15:29:43.316Z

Reserved: 2026-08-12T16:39:35.976Z

Link: CVE-2026-73435

cve-icon Vulnrichment

Updated: 2026-09-16T15:29:35.559Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:51.363

Modified: 2026-09-16T19:09:28.447

Link: CVE-2026-73435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:00:11Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity