CVE-2026-73459

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.

Scoring

Severity
HIGH
CVSS base score
7.4
CVSS vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
EPSS probability
0.16%
CWE
CWE-354
Published
2026-09-15
Last modified
2026-09-16

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs