CVE-2026-73460
Received Received - Intake

IS-IS Graceful Restart Termination in Arista EOS

Vulnerability report for CVE-2026-73460, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may result in traffic loss following a restart event.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Arista EOS devices with IS-IS graceful restart enabled. An unauthenticated attacker can inject a malformed IS-IS LSP PDU packet, causing the graceful restart procedure to end early. This may lead to traffic loss after a restart event.

Detection Guidance

Detecting this vulnerability requires monitoring IS-IS LSP PDU packets for malformed content. Use packet capture tools like tcpdump or Wireshark to inspect IS-IS traffic on affected devices. Check logs for IS-IS graceful restart termination events or unexpected restart procedures.

Impact Analysis

If you use Arista EOS with IS-IS graceful restart enabled, an attacker could exploit this to disrupt network traffic during or after a restart, causing outages or connectivity issues.

Mitigation Strategies

Disable IS-IS graceful restart on affected Arista EOS devices immediately. Apply vendor patches or updates if available. Monitor network traffic for signs of exploitation and isolate affected systems if anomalous behavior is detected.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73460. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart