{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73436","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:39:35.976Z","datePublished":"2026-09-16T09:19:47.800Z","dateUpdated":"2026-09-16T13:50:22.868Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T10:13:39.211Z"},"title":"Security Advisory 0171","descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.</p><p>These issues were discovered internally by Arista, and the company is not aware of any malicious uses of these issues in customer networks.</p>"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","defaultStatus":"unaffected","versions":[{"version":"4.36.0F","lessThanOrEqual":"4.36.1F","status":"affected","versionType":"custom"},{"version":"4.35.0F","lessThanOrEqual":"4.35.5M","status":"affected","versionType":"custom"},{"version":"4.34.0F","lessThanOrEqual":"4.34.7.1M","status":"affected","versionType":"custom"},{"version":"4.33.0F","lessThanOrEqual":"4.33.9M","status":"affected","versionType":"custom"},{"version":"1.0.0","lessThan":"4.33.0F","status":"affected","versionType":"custom"}],"platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010 Series","7010X Series","7020R/R4 Series","7130 Series running EOS","7150 Series","7160 Series","7170 Series","7050X/X2/X3/X4 Series","7060X/X2/X4/X5/X6 Series","7250X Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73436, the following condition must be met:\n\nOSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.\n\n  switch>show ip ospf segment-routing\n  SPF Instance ID: 1\n  ...\n\nIf OSPFv2 segment routing is not configured, then there is no exposure to this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73436, the following condition must be met:</p><p>OSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.</p><pre>switch>show ip ospf segment-routing\nSPF Instance ID: 1\n...</pre><p>If OSPFv2 segment routing is not configured, then there is no exposure to this issue.</p>"}]}],"workarounds":[{"lang":"en","value":"No mitigation is available for CVE-2026-73436.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>No mitigation is available for CVE-2026-73436.</p>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73436 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n- 4.35.6M and later releases in the 4.35.x train\n- 4.34.8M and later releases in the 4.34.x train\n- 4.33.10M and later releases in the 4.33.x train\n\nNo hotfix is available for CVE-2026-73436.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.</p><p>CVE-2026-73436 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li><li>4.33.10M and later releases in the 4.33.x train</li></ul><p>No hotfix is available for CVE-2026-73436.</p>"}]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":6.5,"baseSeverity":"MEDIUM"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseScore":6,"baseSeverity":"MEDIUM"}}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","cweId":"CWE-1284","description":"CWE-1284 Improper Validation of Specified Quantity in Input"}]},{"descriptions":[{"type":"CWE","lang":"en","cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24727-security-advisory-0171","name":"Security Advisory 0171","tags":["vendor-advisory"]}],"source":{"advisory":"Security Advisory 0171","defects":["BUG 1843812"],"discovery":"INTERNAL"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T13:50:10.659104Z","id":"CVE-2026-73436","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T13:50:22.868Z"}}]}}