Impact
Arista EOS systems that have OSPFv2 and OSPFv2 segment routing enabled are vulnerable to a specially crafted OSPFv2 packet that can cause the OSPF process to restart unexpectedly. The flaw originates from an underlying buffer under‑read when parsing the packet, allowing an attacker to trigger an OSPF restart. This results in the loss of routing information and temporary network outages, affecting the availability of services reliant on OSPF connectivity.
Affected Systems
The vulnerability affects Arista Networks EOS releases that are older than the fix. Specifically, any EOS version preceding 4.33.10M, 4.34.8M, 4.35.6M, or 4.36.2F in their respective trains is impacted. The issue is resolved in all later releases within the 4.33.x, 4.34.x, 4.35.x, and 4.36.x trains.
Risk and Exploitability
With a CVSS score of 6.0, the vulnerability carries a moderate risk rating. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack requires an adjacent OSPF neighbor or a device with OSPFv2 segment routing to send a malicious packet, meaning a local network connection or compromised device is sufficient for exploitation.
OpenCVE Enrichment