Description
On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Published: 2026-09-16
Score: 7 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. CVE-2026-73435 has been fixed in the following releases: - 4.36.2F and later releases in the 4.36.x train - 4.35.6M and later releases in the 4.35.x train - 4.34.7.1M and later releases in the 4.34.x train - 4.33.10M and later releases in the 4.33.x train A hotfix is available for the following releases: 4.36.1F, 4.35.5M, 4.34.7M, 4.33.9M. URL: https://www.arista.com/support/advisories-notices/sa-download/?sa171-SecurityAdvisory171_CVE-2026-73435.swix SWIX hash (SHA512): 4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7 Note: Installing/uninstalling the SWIX will cause the Ospf process to restart.


Vendor Workaround

No mitigation is available for CVE-2026-73435.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.
Title Security Advisory 0171
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-16T10:13:38.708Z

Reserved: 2026-08-12T16:39:35.976Z

Link: CVE-2026-73435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T10:16:51.363

Modified: 2026-09-16T11:16:42.040

Link: CVE-2026-73435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses