CVE-2026-73446
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.25%
- CWE
- CWE-696
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2026-44108 — Firewall bypass during shutdown
- CVE-2021-31379 — Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
- CVE-2021-22569 — Denial of Service of protobuf-java parsing procedure
- CVE-2025-31485 — GraphQL grant on a property might be cached with different objects
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2024-24853 — Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Process
- CVE-2023-33224 — SolarWinds Platform Incorrect Behavior Order Vulnerability
- CVE-2025-0150 — Zoom Workplace Apps for iOS - Incorrect Behavior Order