On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The recommended resolution is to upgrade to a fixed software version.


Workaround

No workaround is available for this issue.

History

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.
Title Security Advisory 0160
Weaknesses CWE-696
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-15T23:08:19.771Z

Reserved: 2026-08-12T16:42:47.920Z

Link: CVE-2026-73446

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T00:17:05.000

Modified: 2026-09-16T00:17:05.000

Link: CVE-2026-73446

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses