Description
On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An attacker can send a crafted IS‑IS LSP PDU to a device running Arista EOS with IS‑IS enabled; this causes the legitimate LSP to be purged from the link‑state database, resulting in loss of traffic for routes that used that LSP. The flaw originates from improper handling of incoming PDU data, identified as CWE‑354.

Affected Systems

The vulnerability affects Arista Networks EOS platforms that have IS‑IS routing configured. No specific EOS release numbers are listed, so all EOS versions with IS‑IS enabled are potentially impacted.

Risk and Exploitability

The CVSS score of 7 indicates a medium‑to‑high severity. The EPSS score is below 1 %, suggesting that exploitation has not yet been widely observed. The issue is not listed in the CISA KEV catalog, and no workaround is available. An unauthenticated attacker who can inject crafted IS‑IS LSP PDUs may exploit the flaw, although the limited EPSS implies a low probability of real‑world attacks at present.

Generated by OpenCVE AI on September 16, 2026 at 18:05 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a fixed software version.


Vendor Workaround

No workaround is available for this issue.


OpenCVE Recommended Actions

  • Upgrade to the latest Arista EOS version that contains the IS‑IS LSP fix
  • If IS‑IS routing is not required, disable the protocol to eliminate the attack surface
  • Monitor system routing tables and link‑state database for unexpected changes or loss of LSPs
  • Contact Arista support for guidance on hardening IS‑IS processing if the upgrade cannot be applied immediately

Generated by OpenCVE AI on September 16, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.
Title Security Advisory 0160
Weaknesses CWE-354
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T19:34:44.583Z

Reserved: 2026-08-12T16:45:03.511Z

Link: CVE-2026-73459

cve-icon Vulnrichment

Updated: 2026-09-16T19:34:41.330Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T00:17:05.213

Modified: 2026-09-16T20:17:27.570

Link: CVE-2026-73459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T18:15:15Z

Weaknesses
  • CWE-354

    Improper Validation of Integrity Check Value