Unexpected OSPF Restart Issue in Arista EOS Products
CVE-2026-73436

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73436?

An attacker could exploit a vulnerability on platforms running Arista EOS configured with OSPFv2 and OSPFv2 segment routing. A crafted OSPFv2 packet from a neighboring OSPF device may trigger an unexpected restart of the OSPF process, leading to potential disruptions in network routing and communication. It is crucial for organizations utilizing Arista EOS to assess their configurations and apply any necessary mitigations to safeguard against this vulnerability.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7.1M

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.