On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
PUBLISHED5.2CWE-696
Security Advisory 0160
Problem type
Affected products
Arista Networks
EOS
<= 4.36.1F - AFFECTED
<= 4.35.5M - AFFECTED
<= 4.34.7.1M - AFFECTED
<= 4.33.9M - AFFECTED
< 4.33.0F - AFFECTED
< 4.32.0F - AFFECTED
References
GitHub Security Advisories
GHSA-gq4c-29w8-926p
On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an...
https://github.com/advisories/GHSA-gq4c-29w8-926pOn affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-73446Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-73446",
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"dateUpdated": "2026-09-15T23:08:19.771Z",
"dateReserved": "2026-08-12T16:42:47.920Z",
"datePublished": "2026-09-15T23:08:19.771Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista",
"dateUpdated": "2026-09-15T23:08:19.771Z"
},
"title": "Security Advisory 0160",
"descriptions": [
{
"lang": "en",
"value": "On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.</p>"
}
]
}
],
"affected": [
{
"vendor": "Arista Networks",
"product": "EOS",
"defaultStatus": "unaffected",
"versions": [
{
"version": "4.36.0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "4.36.1F"
},
{
"version": "4.35.0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "4.35.5M"
},
{
"version": "4.34.0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "4.34.7.1M"
},
{
"version": "4.33.0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "4.33.9M"
},
{
"version": "4.32.0",
"status": "affected",
"versionType": "custom",
"lessThan": "4.33.0F"
},
{
"version": "4.31.0",
"status": "affected",
"versionType": "custom",
"lessThan": "4.32.0F"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-696: Incorrect Behavior Order",
"cweId": "CWE-696",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24716-security-advisory-0160",
"name": "Security Advisory 0160",
"tags": [
"vendor-advisory"
]
}
],
"impacts": [
{
"capecId": "CAPEC-272",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-272 Protocol Manipulation"
}
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"configurations": [
{
"lang": "en",
"value": "IS-IS must be enabled on a broadcast (LAN) interface AND there should be an active IS-IS adjacency on that interface:\n\n\n\nswitch(config-router-isis)#show active\nrouter isis 1\n net 49.0001.1111.1111.1001.00\nswitch(config-if-Et1)#show active\ninterface Ethernet1\n isis enable 1\n\n\n\nswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n\n\n Interface Ethernet1:\n Index: 4 SNPA: 2:2:0:1:0:0\n MTU: 1497 Type: broadcast\n Supported address families: IPv4, IPv6\n Area proxy boundary is disabled\n BFD IPv4 is disabled\n BFD IPv6 is disabled\n Hello padding is enabled\n Level 1:\n Metric: 10, Number of adjacencies: 1\n LAN-ID: 1111.1111.1001.04, Priority: 64\n DIS: 1111.1111.1001, DIS priority: 64\n Authentication mode: None\n TI-LFA protection is disabled for IPv4\n TI-LFA protection is disabled for IPv6\n Adjacency 1111.1111.1002:\n State: UP, Level: 1 Type: Level 1 IS\n Advertised hold time: 9\n Neighbor supported address families: IPv4, IPv6\n Address family match: Enabled\n SNPA: 2:2:0:2:0:0, Priority: 64\n IPv4 interface address: 10.0.0.2\n IPv6 interface address: fe80::2:ff:fe02:0\n Area addresses: 49.0001\n\n\n\n\n\nIf IS-IS is not configured OR IS-IS is configured only on point-to-point interfaces, there is no exposure to this issue.\n\n\n\n\n\nswitch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n \n Interface Ethernet1:\n Index: 4 SNPA: P2P\n MTU: 1497 Type: point-to-point\n Supported address families: IPv4, IPv6\n Area proxy boundary is disabled\n BFD IPv4 is disabled\n BFD IPv6 is disabled\n Hello padding is enabled\n Local fast flooding is disabled\n Level 1:\n Metric: 10, Number of adjacencies: 1\n Link-ID: 04\n Authentication mode: None\n TI-LFA protection is disabled for IPv4\n TI-LFA protection is disabled for IPv6\n Adjacency 1111.1111.1002:\n State: UP, Level: 1 Type: Level 1 IS\n Advertised hold time: 30\n Neighbor supported address families: IPv4, IPv6\n Address family match: Enabled\n IPv4 interface address: 1.0.0.2\n IPv6 interface address: fe80::2:ff:fe02:0\n Area addresses: 49.0001\n Peer fast flooding is disabled",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>IS-IS must be enabled on a broadcast (LAN) interface AND there should be an active IS-IS adjacency on that interface:</p><pre>switch(config-router-isis)#show active\nrouter isis 1\n net 49.0001.1111.1111.1001.00\nswitch(config-if-Et1)#show active\ninterface Ethernet1\n isis enable 1<br><br><pre>switch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n<br>\n Interface Ethernet1:\n Index: 4 SNPA: 2:2:0:1:0:0\n MTU: 1497 Type: broadcast\n Supported address families: IPv4, IPv6\n Area proxy boundary is disabled\n BFD IPv4 is disabled\n BFD IPv6 is disabled\n Hello padding is enabled\n Level 1:\n Metric: 10, Number of adjacencies: 1\n LAN-ID: 1111.1111.1001.04, Priority: 64\n DIS: 1111.1111.1001, DIS priority: 64\n Authentication mode: None\n TI-LFA protection is disabled for IPv4\n TI-LFA protection is disabled for IPv6\n Adjacency 1111.1111.1002:\n State: UP, Level: 1 Type: Level 1 IS\n Advertised hold time: 9\n Neighbor supported address families: IPv4, IPv6\n Address family match: Enabled\n SNPA: 2:2:0:2:0:0, Priority: 64\n IPv4 interface address: 10.0.0.2\n IPv6 interface address: fe80::2:ff:fe02:0\n Area addresses: 49.0001</pre></pre><p>If IS-IS is not configured OR IS-IS is configured only on point-to-point interfaces, there is no exposure to this issue.<br><br></p><pre>switch#show isis interface detail\nIS-IS Instance: 1 VRF: default\n \n Interface Ethernet1:\n Index: 4 SNPA: P2P\n MTU: 1497 Type: point-to-point\n Supported address families: IPv4, IPv6\n Area proxy boundary is disabled\n BFD IPv4 is disabled\n BFD IPv6 is disabled\n Hello padding is enabled\n Local fast flooding is disabled\n Level 1:\n Metric: 10, Number of adjacencies: 1\n Link-ID: 04\n Authentication mode: None\n TI-LFA protection is disabled for IPv4\n TI-LFA protection is disabled for IPv6\n Adjacency 1111.1111.1002:\n State: UP, Level: 1 Type: Level 1 IS\n Advertised hold time: 30\n Neighbor supported address families: IPv4, IPv6\n Address family match: Enabled\n IPv4 interface address: 1.0.0.2\n IPv6 interface address: fe80::2:ff:fe02:0\n Area addresses: 49.0001\n Peer fast flooding is disabled<br></pre>"
}
]
}
],
"workarounds": [
{
"lang": "en",
"value": "No workaround is available for this issue.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>No workaround is available for this issue.</p>"
}
]
}
],
"solutions": [
{
"lang": "en",
"value": "The recommended resolution is to upgrade to a fixed software version.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<p>The recommended resolution is to upgrade to a fixed software version.</p>"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "This issue was discovered internally by Arista and the company is not aware of any malicious uses of these issues in customer networks.",
"type": "finder"
}
]
}
}
}