Bidirectional Forwarding Detection Vulnerability in Arista EOS
CVE-2026-73458

9.2CRITICAL

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-73458?

A vulnerability exists in Arista EOS when authenticated Bidirectional Forwarding Detection (BFD) sessions are used. An attacker can exploit this weakness by sending a specially crafted packet, causing these BFD sessions to fail. The disruption can lead to unintended network changes as routing protocols depend on the status of BFD sessions to operate correctly. Network administrators should be aware of this issue to mitigate potential impacts on network stability and security.

Affected Version(s)

EOS 710 Series 4.36.0 <= 4.36.1F

EOS 710 Series 4.35.0 <= 4.35.5M

EOS 710 Series 4.34.0 <= 4.34.7M

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered internally by Arista.
.