Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-73458: Arista EOS BFD sessions can be dropped by crafted packet

CVE-2026-73458 · published 11 days ago
Summary

Arista EOS devices that use authenticated Bidirectional Forwarding Detection may lose their BFD sessions if they receive a specially formed network packet. When a BFD session goes down, routing protocols that rely on it may change how traffic is routed, potentially causing temporary network disruptions. Update the EOS software to the latest version or disable BFD authentication until a fix is applied.

What to do
  • Update arista networks eos to version 4.36.2F.
Affected software
VendorProductAffected versions
arista networks eos <= 4.36.1F
Fix: upgrade to 4.36.2F
Original advisory text
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This ma...
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).
Severity
9.2 Critical
CVSS 3.1: 8.2 (MITRE)
Exploitation
EPSS <1%
Type
CWE-303Incorrect Implementation of Authentication Algorithm
Timeline
Published15 Sep 2026
Updated27 Sep 2026
First seen15 Sep 2026
Sources
CVE-2026-73458 · MITRE
Track software like this
Free during beta