CVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H
- EPSS probability
- 0.38%
- CWE
- CWE-303
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
- Arista Networks EOS
Weakness type
Related vulnerabilities
- CVE-2024-7593 — Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remo
- CVE-2022-20695 — Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
- CVE-2025-13390 — WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover
- CVE-2024-4985 — An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig
- CVE-2025-66489 — Cal.com Authentication Bypass via bad TOTP + password checks
- CVE-2025-12421 — Account Takeover via Code Exchange Endpoint
- CVE-2025-12419 — Account takeover on OAuth/OpenID-enabled servers
- CVE-2022-39366 — DataHub missing JWT signature check