Impact
An unauthenticated attacker able to send a crafted malformed IS‑IS LSP PDU packet can force the IS‑IS graceful restart process on Arista EOS to terminate early. The premature termination can interrupt network traffic during the restart event, leading to a loss of connectivity for affected routes. The vulnerability hinges on a logic flaw that allows this packet injection, classified as CWE‑863.
Affected Systems
All devices running Arista EOS with the IS‑IS graceful restart feature enabled are potentially affected. No specific product versions are listed as impacted, so any EOS release that includes this feature is included in the risk scope.
Risk and Exploitability
The CVSS score of 7 indicates a high severity for the potential service disruption. However, the EPSS score of less than 1% suggests a very low probability of exploitation in current network environments. The vulnerability is not listed in the CISA KEV catalog, and there is no official workaround. The likely attack vector is a network‐based injection of malformed packets, and an attacker does not require credentials to exploit this flaw.
OpenCVE Enrichment