Impact
An attacker can send a crafted IS‑IS LSP PDU to a device running Arista EOS with IS‑IS enabled; this causes the legitimate LSP to be purged from the link‑state database, resulting in loss of traffic for routes that used that LSP. The flaw originates from improper handling of incoming PDU data, identified as CWE‑354.
Affected Systems
The vulnerability affects Arista Networks EOS platforms that have IS‑IS routing configured. No specific EOS release numbers are listed, so all EOS versions with IS‑IS enabled are potentially impacted.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity. The EPSS score is below 1 %, suggesting that exploitation has not yet been widely observed. The issue is not listed in the CISA KEV catalog, and no workaround is available. An unauthenticated attacker who can inject crafted IS‑IS LSP PDUs may exploit the flaw, although the limited EPSS implies a low probability of real‑world attacks at present.
OpenCVE Enrichment