Impact
The vulnerability exists in the OSPFv3 routing protocol implementation on Arista EOS. A specially crafted packet directed at the OSPFv3 agent can cause it to restart unexpectedly, resulting in a loss of OSPF service and network routing disruption. This denial‑of‑service flaw is a manifestation of CWE‑130, an incorrect calculation of buffer limits that can be triggered by malformed input.
Affected Systems
Affected EOS releases include 4.33.9M and later in the 4.33.x train, 4.34.7M and later in the 4.34.x train, 4.35.5M and later in the 4.35.x train, and 4.36.1F and later in the 4.36.x train. A hotfix (version 1.0) is available for the older releases 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M.
Risk and Exploitability
The CVSS score of 8.9 marks this as a high‑severity flaw. The EPSS score of less than 1% indicates a low current exploitation probability, but the vulnerability is not present in the CISA KEV catalog. Based on the packet‑based nature of the flaw, the likely attack vector is the network, and the exploit can be performed remotely without special privileges. The main impact is a temporary loss of OSPF routing and network availability, with no direct confidentiality or integrity breach.
OpenCVE Enrichment