OSPFv2 Vulnerability in Arista EOS Impacting Network Stability
CVE-2026-73435

7HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73435?

A vulnerability exists in Arista EOS when OSPFv2 is configured. An unauthenticated attacker on the same broadcast segment can send a specially crafted OSPFv2 packet, leading to adjacency flapping and potential packet loss. This disruption may significantly impact routing within the OSPF domain, affecting overall network stability and performance.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.