CVE-2026-73458
Received Received - Intake

BFD Session Downtime in Arista EOS

Vulnerability report for CVE-2026-73458, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-303 The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with BFD sessions enabled. A specially crafted packet can force BFD sessions to go down, potentially causing network disruptions as routing protocols rely on these sessions for status monitoring.

Detection Guidance

Detect affected Arista EOS devices by checking for BFD session configurations and monitoring for unexpected session drops. Use commands like 'show bfd peers' to verify active sessions and 'show logging' to identify BFD-related errors or disconnections.

Impact Analysis

The impact includes network instability due to unexpected BFD session failures. This may lead to routing changes, degraded performance, or loss of connectivity depending on the network's reliance on BFD for failover detection.

Compliance Impact

This vulnerability may cause network disruptions by forcing BFD sessions to go down, potentially leading to routing changes. Such disruptions could impact data transmission integrity and availability, which are critical for compliance with standards like GDPR (data integrity and availability) and HIPAA (network reliability for protected health information). However, the provided CVE details do not explicitly link this vulnerability to specific compliance impacts.

Mitigation Strategies

Apply the latest Arista EOS patches or updates addressing BFD vulnerabilities. Disable BFD sessions if not critical, or restrict access to authenticated sessions. Monitor network traffic for malformed BFD packets and update firewall rules to filter suspicious traffic.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73458. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart