Impact
On Arista EOS systems with Open Shortest Path First (OSPFv2) and authentication enabled, an attacker can send a specially crafted OSPFv2 packet from an unauthenticated host on the same broadcast segment. The packet triggers adjacency flapping and causes packet loss across the OSPF domain, which destabilizes routing and leads to denial of service for the network relying on OSPF for routing.
Affected Systems
Arista Networks EOS firmware in the 4.36.x (fixed starting 4.36.2F), 4.35.x (fixed 4.35.6M), 4.34.x (fixed 4.34.7.1M), and 4.33.x (fixed 4.33.10M) release trains is affected. Hotfixes are available for 4.36.1F, 4.35.5M, 4.34.7M, and 4.33.9M. The issue only manifests on platforms running OSPFv2 with authentication configured.
Risk and Exploitability
The CVSS score of 7.0 denotes moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation; the vulnerability is not listed in CISA KEV. It is locally exploitable by an attacker who can inject OSPF packets on the same broadcast segment. Successful exploitation can lead to OSPF adjacency flapping and consequent packet loss, effectively causing denial‑of‑service for networks relying on OSPF for routing.
OpenCVE Enrichment