Impact
A specially crafted OSPFv2 packet sent by an adjacent OSPF neighbor can cause the OSPF process on Arista EOS devices to restart unexpectedly. This restart terminates the current OSPF state and forces the router to rebuild its routing tables, which interrupts routing decisions and can lead to temporary network outages and loss of connectivity for services that depend on OSPF.
Affected Systems
The vulnerability affects Arista Networks EOS releases older than the fixed versions: any EOS release prior to 4.36.2F in the 4.36.x train, 4.35.6M in the 4.35.x train, 4.34.8M in the 4.34.x train, or 4.33.10M in the 4.33.x train. Systems must also have OSPFv2 and OSPFv2 segment routing enabled to be vulnerable.
Risk and Exploitability
With a CVSS score of 6.0, the vulnerability has a moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation in the general population, and the issue is not listed in the CISA KEV catalog, implying no known active exploitation. The exploit requires an adjacent OSPF neighbor or a device with OSPFv2 segment routing to send a malicious packet, so an attacker must be on the same network segment or have compromised a neighboring device.
OpenCVE Enrichment