Impact
A crafted OSPFv2 packet from an unauthenticated host on the same broadcast segment, when OSPFv2 authentication is enabled, triggers adjacency flapping and packet loss, potentially disrupting routing across the OSP compromise network availability by causing routing instability.
Affected Systems
Arista Networks EOS firmware in the 4.36.x, 4.35.x, 4.34.x, and 4.33.x release trains is affected. Fixed releases begin with 4.36.2F 4.34.7.1M, and 4.33.10M respectively, and hotfixes are available for 4.36.1F, 4.35.5M, 4.34.7M, and 4.33.9M.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. With no EPSS data, the exact exploitation probability is unknown, but the vulnerability is locally exploitable by an attacker on the same broadcast segment. Because it causes OSPF adjacency flapping and can lead to packet loss, it constitutes a serious denial‑of‑service risk for any network relying on OSPF for routing.
OpenCVE Enrichment