GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: injected IS-IS LSP PDU purges a legitimate LSP from the link-state database

CVSS 7.0CVE-2026-73459Firmware, BMC & network fabriccurated

Impact

An unauthenticated attacker who can inject IS-IS LSPs makes the switch purge a legitimate LSP from its link-state database, so the topology that switch computes no longer matches reality and traffic depending on the purged information is lost. Unlike an adjacency drop, an LSP purge propagates through the IS-IS domain, so a single injection point can distort routing well beyond the segment it was sent on. On a GPU underlay that carries RoCE and parallel-filesystem traffic this shows up as partial blackholing that is hard to attribute, and in-flight collective operations fail. Availability only - no claim of data exposure.

Who can reach it

Unauthenticated attacker with adjacent-network access able to inject IS-IS PDUs toward a switch running IS-IS. No credentials required.

What to do

Upgrade to the fixed EOS release or install the hotfix from Arista security advisory 0160 - a switch reload, so sequence it leaf by leaf with racks drained or dual-homed. Interim hardening is IS-IS authentication and keeping IS-IS off any port an untrusted host can reach. Fixed versions are only in Arista's advisory.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.