Impact
The vulnerability enables an unauthenticated attacker to send a specially crafted IS-IS Hello PDU that causes an Arista EOS router to tear down an established IS-IS adjacency. As a result, traffic is disrupted and IP reachability for prefixes advertised through that adjacency is lost. The weakness is categorized as CWE‑696, representing a failure to properly handle external input that leads to unintended behavior.
Affected Systems
Arista Networks EOS is affected; specific software versions are not listed in the advisory, so all releases prior to the vendor’s fixed version should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack from an adversary that can reach the device’s broadcast interfaces, and no authentication is required to exploit it. Based on the description, it is inferred that the attacker would need to be able to inject a malicious IS-IS Hello PDU into the target’s network.
OpenCVE Enrichment