OSPFv3 Configuration Vulnerability in Arista EOS Product
CVE-2026-73438

7HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73438?

The vulnerability affects platforms running Arista EOS configured with Open Shortest Path First version 3 (OSPFv3). An unauthenticated attacker within the same OSPFv3 broadcast domain can exploit this flaw by sending specially crafted packets that trigger an unexpected restart of the OSPFv3 agent. This incident leads to the loss of all OSPFv3 adjacencies on the impacted device, resulting in potential routing disruptions across the entire OSPF domain until the agent is fully recovered. Arista has yet to report any known malicious exploitation of this vulnerability in customer networks.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7M

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dravanet Inc.
.