Description
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability enables an unauthenticated attacker to send a specially crafted IS-IS Hello PDU that causes an Arista EOS router to tear down an established IS-IS adjacency. As a result, traffic is disrupted and IP reachability for prefixes advertised through that adjacency is lost. The weakness is categorized as CWE‑696, representing a failure to properly handle external input that leads to unintended behavior.

Affected Systems

Arista Networks EOS is affected; specific software versions are not listed in the advisory, so all releases prior to the vendor’s fixed version should be considered vulnerable.

Risk and Exploitability

The CVSS score of 7 indicates a moderate severity, and the EPSS score of < 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based attack from an adversary that can reach the device’s broadcast interfaces, and no authentication is required to exploit it. Based on the description, it is inferred that the attacker would need to be able to inject a malicious IS-IS Hello PDU into the target’s network.

Generated by OpenCVE AI on September 16, 2026 at 18:07 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a fixed software version.


Vendor Workaround

No workaround is available for this issue.


OpenCVE Recommended Actions

  • Update Arista EOS to the vendor‑recommended fixed software version.
  • If an immediate upgrade is not feasible, disable IS‑IS on broadcast interfaces or re‑configure the network to use unicast mode, thereby preventing the crafted Hello PDU from affecting adjacency state.
  • Implement monitoring for unexpected IS‑IS adjacency withdrawals and check routing tables for loss of reachability; investigate any sudden route changes promptly.

Generated by OpenCVE AI on September 16, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Title Security Advisory 0160
Weaknesses CWE-696
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T19:34:18.384Z

Reserved: 2026-08-12T16:42:47.920Z

Link: CVE-2026-73446

cve-icon Vulnrichment

Updated: 2026-09-16T19:34:14.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T00:17:05.000

Modified: 2026-09-16T20:17:26.997

Link: CVE-2026-73446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T18:15:15Z

Weaknesses