Impact
A specially crafted packet can cause authenticated Bidirectional Forwarding Detection sessions on affected Arista EOS platforms to fail. This failure leads to changes in routing tables because many protocols monitor B be rerouted through less optimal or insecure paths. The vulnerability is associated with CWE‑303, indicating an improper limitation or control condition. The impact can degrade network availability and reliability for all users of the affected network devices.
Affected Systems
Arista Networks EOS firmware versions are impacted. The following releases contain the fix: 4.36.2F and later within the 4.36.x train, 4.35.6M and later within the 4.35.x train, 4.34.8M and later within the 4.34.x train, and 4.33.9M and later within the 4.33.x train. Devices running any earlier versions of these firmware trains are vulnerable.
Risk and Exploitability
The CVSS score of 9.2 classifies this flaw as Critical. EPSS information is unavailable, but the lack of known public exploitation and absence from KEV suggest exploitation risk is not yet widespread. The likely attack vector involves the network, where an attacker capable of sending crafted BFD packets—either through local network access, compromised BFD peers, or devices with exposed BFD interfaces—could trigger session failures. The vulnerability requires authenticated BFD sessions to be present; without them, the flaw has no effect.
OpenCVE Enrichment