Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5477 articles · 220951 vulns · 37/41 feeds (7d)
← Back to list
8.2
CVE-2026-73435PATCHED
arista · eos

Security Advisory 0171

Description

On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.

Affected Products

VendorProductVersions
aristaeos4.36.0F, 4.35.0F, 4.34.0F, 4.33.0F, 1.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristaeoscert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24727-security-advisory-0171(vendor-advisory)

Related News (2 articles)

Tier B
BSI Advisories5d ago
[NEU] [mittel] Arista EOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-73435 | Arista EOS up to 4.36.1F OSPFv2 input validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.2 HIGH
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
4.33.0F
CWECWE-345
PublishedSep 16, 2026
Trending Score20
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93952EXPKEV
Security Advisory 0183
Trending: 130
HIGHCVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Trending: 24
CRITICALCVE-2026-73456
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Trending: 23
CRITICALCVE-2026-73453
Security Advisory 0174
Trending: 22
MEDIUMCVE-2026-19641
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Trending: 22

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 16, 2026
Discovered by ZDM
Sep 16, 2026
Patch Available
Sep 16, 2026