CVE-2026-73446
Received Received - Intake

IS-IS Adjacency Termination in Arista EOS

Vulnerability report for CVE-2026-73446, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacency. This may result in traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-07
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-696 The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices running IS-IS on broadcast interfaces. An unauthenticated attacker can send a specially crafted IS-IS Hello Protocol Data Unit (PDU) to force the device to terminate an established IS-IS adjacency. This leads to traffic disruption and loss of IP reachability for prefixes advertised through that adjacency.

Detection Guidance

Detecting this vulnerability requires monitoring IS-IS adjacency status and inspecting IS-IS PDUs. Check for unexpected adjacency teardowns using commands like 'show isis adjacency' on Arista EOS devices. Monitor syslog or network logs for IS-IS PDU errors or malformed packets.

Impact Analysis

The impact includes network outages or degraded performance due to terminated adjacencies, loss of connectivity for affected network prefixes, and potential service disruptions for users relying on those routes. Attackers could exploit this to cause denial of service without needing authentication.

Mitigation Strategies

Immediately update Arista EOS to the latest patched version. Disable IS-IS on broadcast interfaces if not required. Enable IS-IS authentication if configured. Monitor network traffic for unusual IS-IS PDUs and restrict access to IS-IS ports (TCP/UDP 1024-1025).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73446. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart