CVE-2026-73459
Received Received - Intake

IS-IS LSP Injection Leading to Database Purge in Arista EOS

Vulnerability report for CVE-2026-73459, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic loss.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista arista_eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices running IS-IS. An unauthenticated attacker can inject a specially crafted IS-IS LSP PDU to cause the legitimate LSP to be purged from the IS-IS link-state database, potentially leading to traffic loss.

Impact Analysis

The vulnerability may cause unexpected purging of legitimate LSPs in the IS-IS database, resulting in network traffic loss. This can disrupt network operations and lead to service outages.

Mitigation Strategies

Immediately disable IS-IS on affected Arista EOS devices or apply patches from Arista if available. Monitor network traffic for unexpected LSP purges and isolate suspicious IS-IS PDUs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73459. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart