Database/Firmware, BMC & network fabric

Arista EOS: crafted OSPFv3 packets restart the Ospf3 agent and drop all adjacencies
Impact
An unauthenticated attacker on the same OSPFv3 broadcast domain can send a packet sequence that restarts the Ospf3 agent. Every OSPFv3 adjacency on the device drops, and the reconvergence ripples out across the OSPF domain until the agent recovers. On a routed fabric this is not one switch going quiet: routes through the affected device withdraw and return, and long-running distributed training jobs that cannot tolerate a stall in the interconnect fail rather than degrade. Repeatable by the attacker, so the disruption is sustainable. Arista credits an external reporter and says it is not aware of exploitation in customer networks.
Who can reach it
Unauthenticated, on the OSPFv3 broadcast domain - a host or compromised device sharing an L2 segment with an OSPFv3-speaking interface. The CVSS vector notes an attack requirement (AT:P), so exploitation depends on conditions Arista does not detail.
What to do
Apply the EOS release or hotfix named in Arista advisory 0172. As a standing control, OSPFv3 authentication and keeping OSPF-speaking interfaces off segments that carry tenant traffic both reduce who can reach the agent. Expect an upgrade window per affected switch.
References
Related entries
- Arista EOS: crafted IS-IS Hello PDU tears down an established adjacency on a broadcast linkCVE-2026-73446 · Arista EOS IS-IS (Hello PDU handling on broadcast interfaces)High
- Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfacesCVE-2026-73450 · Arista EOS MLAG Dual Primary DetectionHigh
- Arista EOS: injected IS-IS LSP PDU purges a legitimate LSP from the link-state databaseCVE-2026-73459 · Arista EOS IS-IS (LSP PDU processing, link-state database)High
- Arista EOS: malformed IS-IS LSP PDU aborts graceful restart, causing traffic loss on restartCVE-2026-73460 · Arista EOS IS-IS graceful restart (malformed LSP PDU handling)High
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorCVE-2020-25647 · GRUB2 (USB device initialization)Medium
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localCVE-2025-0045 · AMD Secure Processor PCI driver - input validationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.