Description
On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Published: 2026-09-16
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (OSPF Restart)
Action: Patch
AI Analysis

Impact

A specially crafted OSPFv2 packet sent by an adjacent OSPF neighbor can cause the OSPF process on Arista EOS devices to restart unexpectedly. This restart terminates the current OSPF state and forces the router to rebuild its routing tables, which interrupts routing decisions and can lead to temporary network outages and loss of connectivity for services that depend on OSPF.

Affected Systems

The vulnerability affects Arista Networks EOS releases older than the fixed versions: any EOS release prior to 4.36.2F in the 4.36.x train, 4.35.6M in the 4.35.x train, 4.34.8M in the 4.34.x train, or 4.33.10M in the 4.33.x train. Systems must also have OSPFv2 and OSPFv2 segment routing enabled to be vulnerable.

Risk and Exploitability

With a CVSS score of 6.0, the vulnerability has a moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation in the general population, and the issue is not listed in the CISA KEV catalog, implying no known active exploitation. The exploit requires an adjacent OSPF neighbor or a device with OSPFv2 segment routing to send a malicious packet, so an attacker must be on the same network segment or have compromised a neighboring device.

Generated by OpenCVE AI on September 18, 2026 at 11:37 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73436 has been fixed in the following releases: - 4.36.2F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.8M and later releases in the 4.34.x train - 4.33.10M and later releases in the 4.33.x train No hotfix is available for CVE-2026-73436.


Vendor Workaround

No mitigation is available for CVE-2026-73436.


OpenCVE Recommended Actions

  • Upgrade Arista EOS to the latest release in the affected train (e.g., 4.36.2F or later in the 4.36.x series, or the latest in the 4.35.x, 4.34.x, or 4.33.x series).
  • Disable or isolate OSPFv2 and OSPFv2 segment routing from untrusted neighbors, or remove the protocol where it is not needed.
  • Monitor OSPF logs for unexpected restarts or routing table changes and investigate any anomalies promptly.

Generated by OpenCVE AI on September 18, 2026 at 11:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.
Title Security Advisory 0171
Weaknesses CWE-125
CWE-1284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T13:50:22.868Z

Reserved: 2026-08-12T16:39:35.976Z

Link: CVE-2026-73436

cve-icon Vulnrichment

Updated: 2026-09-16T13:50:16.644Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:51.550

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-73436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:45:07Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-1284

    Improper Validation of Specified Quantity in Input