GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: crafted OSPFv3 packets restart the Ospf3 agent and drop all adjacencies

CVSS 7.0CVE-2026-73438Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker on the same OSPFv3 broadcast domain can send a packet sequence that restarts the Ospf3 agent. Every OSPFv3 adjacency on the device drops, and the reconvergence ripples out across the OSPF domain until the agent recovers. On a routed fabric this is not one switch going quiet: routes through the affected device withdraw and return, and long-running distributed training jobs that cannot tolerate a stall in the interconnect fail rather than degrade. Repeatable by the attacker, so the disruption is sustainable. Arista credits an external reporter and says it is not aware of exploitation in customer networks.

Who can reach it

Unauthenticated, on the OSPFv3 broadcast domain - a host or compromised device sharing an L2 segment with an OSPFv3-speaking interface. The CVSS vector notes an attack requirement (AT:P), so exploitation depends on conditions Arista does not detail.

What to do

Apply the EOS release or hotfix named in Arista advisory 0172. As a standing control, OSPFv3 authentication and keeping OSPF-speaking interfaces off segments that carry tenant traffic both reduce who can reach the agent. Expect an upgrade window per affected switch.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.