Description
On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Published: 2026-09-16
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (OSPF Restart)
Action: Patch
AI Analysis

Impact

Arista EOS systems that have OSPFv2 and OSPFv2 segment routing enabled are vulnerable to a specially crafted OSPFv2 packet that can cause the OSPF process to restart unexpectedly. The flaw originates from an underlying buffer under‑read when parsing the packet, allowing an attacker to trigger an OSPF restart. This results in the loss of routing information and temporary network outages, affecting the availability of services reliant on OSPF connectivity.

Affected Systems

The vulnerability affects Arista Networks EOS releases that are older than the fix. Specifically, any EOS version preceding 4.33.10M, 4.34.8M, 4.35.6M, or 4.36.2F in their respective trains is impacted. The issue is resolved in all later releases within the 4.33.x, 4.34.x, 4.35.x, and 4.36.x trains.

Risk and Exploitability

With a CVSS score of 6.0, the vulnerability carries a moderate risk rating. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack requires an adjacent OSPF neighbor or a device with OSPFv2 segment routing to send a malicious packet, meaning a local network connection or compromised device is sufficient for exploitation.

Generated by OpenCVE AI on September 16, 2026 at 13:21 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73436 has been fixed in the following releases: - 4.36.2F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.8M and later releases in the 4.34.x train - 4.33.10M and later releases in the 4.33.x train No hotfix is available for CVE-2026-73436.


Vendor Workaround

No mitigation is available for CVE-2026-73436.


OpenCVE Recommended Actions

  • Upgrade Arista EOS to the latest release in the 4.36.x train (v4.36.2F or later), or to the latest release in the 4.35.x, 4.34.x, or 4.33.x trains if using those series.
  • Confirm the OSPFv2 and OSPFv2 segment routing configuration on each EOS device to ensure that unnecessary routing protocols are disabled or isolated from untrusted neighbors.
  • Monitor OSPF logs for unexpected restarts or routing table changes as indicators that a crafted packet has been processed, and investigate any anomalies promptly.

Generated by OpenCVE AI on September 16, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Title Security Advisory 0171
Weaknesses CWE-125
CWE-1284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T13:50:22.868Z

Reserved: 2026-08-12T16:39:35.976Z

Link: CVE-2026-73436

cve-icon Vulnrichment

Updated: 2026-09-16T13:50:16.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:51.550

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-73436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T13:30:10Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-1284

    Improper Validation of Specified Quantity in Input