Description
On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via premature IS‑IS graceful restart termination
Action: Patch Immediately
AI Analysis

Impact

An unauthenticated attacker able to send a crafted malformed IS‑IS LSP PDU packet can force the IS‑IS graceful restart process on Arista EOS to terminate early. The premature termination can interrupt network traffic during the restart event, leading to a loss of connectivity for affected routes. The vulnerability hinges on a logic flaw that allows this packet injection, classified as CWE‑863.

Affected Systems

All devices running Arista EOS with the IS‑IS graceful restart feature enabled are potentially affected. No specific product versions are listed as impacted, so any EOS release that includes this feature is included in the risk scope.

Risk and Exploitability

The CVSS score of 7 indicates a high severity for the potential service disruption. However, the EPSS score of less than 1% suggests a very low probability of exploitation in current network environments. The vulnerability is not listed in the CISA KEV catalog, and there is no official workaround. The likely attack vector is a network‐based injection of malformed packets, and an attacker does not require credentials to exploit this flaw.

Generated by OpenCVE AI on September 16, 2026 at 18:05 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a fixed software version.


Vendor Workaround

No workaround is available for this issue.


OpenCVE Recommended Actions

  • Upgrade Arista EOS to the fixed software version as recommended by the vendor.
  • If the feature is not required, disable IS‑IS graceful restart to remove the attack surface.
  • Verify network device logs for abrupt IS‑IS restart events and adjust routing policies accordingly.

Generated by OpenCVE AI on September 16, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.
Title Security Advisory 0160
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T19:35:40.181Z

Reserved: 2026-08-12T16:45:03.511Z

Link: CVE-2026-73460

cve-icon Vulnrichment

Updated: 2026-09-16T19:35:35.763Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T00:17:05.397

Modified: 2026-09-16T20:17:28.110

Link: CVE-2026-73460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T18:15:15Z

Weaknesses