Description
On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
Published: 2026-09-16
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: OSPFv3 Agent Crash Leading to Service Disruption
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the OSPFv3 routing protocol implementation on Arista EOS. A specially crafted packet directed at the OSPFv3 agent can cause it to restart unexpectedly, resulting in a loss of OSPF service and network routing disruption. This denial‑of‑service flaw is a manifestation of CWE‑130, an incorrect calculation of buffer limits that can be triggered by malformed input.

Affected Systems

Affected EOS releases include 4.33.9M and later in the 4.33.x train, 4.34.7M and later in the 4.34.x train, 4.35.5M and later in the 4.35.x train, and 4.36.1F and later in the 4.36.x train. A hotfix (version 1.0) is available for the older releases 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M.

Risk and Exploitability

The CVSS score of 8.9 marks this as a high‑severity flaw. The EPSS score of less than 1% indicates a low current exploitation probability, but the vulnerability is not present in the CISA KEV catalog. Based on the packet‑based nature of the flaw, the likely attack vector is the network, and the exploit can be performed remotely without special privileges. The main impact is a temporary loss of OSPF routing and network availability, with no direct confidentiality or integrity breach.

Generated by OpenCVE AI on September 18, 2026 at 10:28 UTC.

Remediation

Vendor Solution

The following EOS releases contain the fix: - 4.33.9M and later in the 4.33.x train - 4.34.7M and later in the 4.34.x train - 4.35.5M and later in the 4.35.x train - 4.36.1F and later in the 4.36.x train A hotfix (version 1.0) is available for 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M.


Vendor Workaround

Configure OSPFv3 IPsec encryption to authenticate/encrypt OSPFv3 packets. Per-interface encryption: switch(config)# interface <interface-name> switch(config-if)# ospfv3 encryption ipsec spi <spi-value> esp aes-256-cbc sha1 passphrase <shared-passphrase> Per-area encryption: switch(config)# router ospfv3 switch(config-router-ospfv3)# address-family ipv4 switch(config-router-ospfv3-af)# area <area-id> encryption ipsec spi <spi-value> esp aes-256-cbc sha1 passphrase <shared-passphrase>


OpenCVE Recommended Actions

  • Upgrade the EOS firmware to any of the patched releases: 4.33.9M or later, 4.34.7M or later, 4.35.5M or later, or 4.36.1F or later.
  • Apply the concrete hotfix 1.0 to the earlier releases: 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M.
  • If a firmware upgrade is delayed, configure OSPFv3 IPsec encryption on all interfaces and areas to authenticate and encrypt OSPFv3 packets.

Generated by OpenCVE AI on September 18, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.
Title Security Advisory 0173
Weaknesses CWE-130
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T17:56:12.396Z

Reserved: 2026-08-12T16:45:03.510Z

Link: CVE-2026-73455

cve-icon Vulnrichment

Updated: 2026-09-16T17:56:08.766Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T10:16:52.243

Modified: 2026-09-16T19:09:28.447

Link: CVE-2026-73455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:43Z

Weaknesses
  • CWE-130

    Improper Handling of Length Parameter Inconsistency