Database/Firmware, BMC & network fabric

Arista EOS: crafted IS-IS Hello PDU tears down an established adjacency on a broadcast link
Impact
An attacker on the same L2 segment as a switch running IS-IS on a broadcast interface can drop an established adjacency, withdrawing every prefix learned across it. On a GPU fleet the IS-IS underlay is what carries storage traffic and east-west RDMA/RoCE routing between leaf and spine, so a dropped adjacency reroutes or blackholes traffic for whole racks at once. Long-running distributed training jobs do not survive a routing flap gracefully - collectives stall or abort, and the loss is fleet-wide rather than per-tenant. No confidentiality or integrity loss is claimed, only availability of reachability.
Who can reach it
Unauthenticated attacker with adjacent-network access - anything that can put frames on a broadcast segment where the switch runs IS-IS. No credentials required.
What to do
Apply the fixed EOS release or hotfix named in Arista security advisory 0160; an EOS upgrade means a scheduled switch reload (or ISSU where the platform supports it), so drain or dual-home the affected racks first. Until then, restrict which ports can carry IS-IS and enable IS-IS authentication where the design allows. Arista's advisory is the only source for affected and fixed versions; nothing further is stated in the record.
References
Related entries
- Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfacesCVE-2026-73450 · Arista EOS MLAG Dual Primary DetectionHigh
- Arista EOS: injected IS-IS LSP PDU purges a legitimate LSP from the link-state databaseCVE-2026-73459 · Arista EOS IS-IS (LSP PDU processing, link-state database)High
- Arista EOS: malformed IS-IS LSP PDU aborts graceful restart, causing traffic loss on restartCVE-2026-73460 · Arista EOS IS-IS graceful restart (malformed LSP PDU handling)High
- GRUB2 (USB device initialization): Out-of-bounds write in grub_usb_device_initialize from a malicious USB descriptorCVE-2020-25647 · GRUB2 (USB device initialization)Medium
- AMD Secure Processor PCI driver - input validation: Improper input validation in the ASP PCI driver lets a localCVE-2025-0045 · AMD Secure Processor PCI driver - input validationMedium
- AMD SEV firmware - RMP write during SNP initialization: A privileged attacker can write to the reverse map page duringCVE-2025-29939 · AMD SEV firmware - RMP write during SNP initializationMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.