{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73458","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:45:03.510Z","datePublished":"2026-09-15T19:30:16.014Z","dateUpdated":"2026-09-15T19:38:38.389Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-15T19:30:16.014Z"},"title":"On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou","datePublic":"2026-09-09T19:27:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-303","description":"CWE-303 Incorrect Implementation of Authentication Algorithm","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange","virtual or physical appliance"],"versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","changes":[{"at":"4.36.2F","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","changes":[{"at":"4.35.6M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7M","changes":[{"at":"4.34.8M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.33.0","lessThanOrEqual":"4.33.8M","changes":[{"at":"4.33.9M","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73458, the following condition must be met:\n\nBFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:\n\n \n\n  *  Password\n  *  Keyed MD5\n  *  Meticulous MD5\n  *  Keyed SHA1\n  *  Meticulous SHA1\n\n\n\n\nTo determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.\n\n\n\nswitch>show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:  Version: 1             - Diagnostic: 0\n              State bit: Up          - Demand bit: 0\n              Poll bit: 0            - Final bit: 0\n              Multiplier: 20         - Length: 38\n              My Discr.: 3471785639  - Your Discr.: 2432996710\n              Min tx interval: 500   - Min rx interval: 500\n              Min Echo interval: 500\n\n\n \n\n\n\nIf BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:\n\n\n\nswitch>show running-config section bfd\nswitch>\n\n\n \n\n\n\nIf BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:\n\n\n\nswitch>show bfd peers detail\nswitch>\n\n\n \n\n\n\nIf BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:\n\n\n\nswitch>show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:  Version: 1             - Diagnostic: 0\n              State bit: Up          - Demand bit: 0\n              Poll bit: 0            - Final bit: 0\n              Multiplier: 20         - Length: 24\n              My Discr.: 3471785639  - Your Discr.: 2432996710\n              Min tx interval: 500   - Min rx interval: 500\n              Min Echo interval: 500","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73458, the following condition must be met:</p><div>BFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:</div><div>&nbsp;</div><ul><li>Password</li><li>Keyed MD5</li><li>Meticulous MD5</li><li>Keyed SHA1</li><li>Meticulous SHA1</li></ul><p>To determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.</p><pre>switch&gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:&nbsp; Version: 1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Diagnostic: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;State bit: Up&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Demand bit: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Poll bit: 0&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Final bit: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Multiplier: 20 &nbsp; &nbsp; &nbsp; &nbsp; - Length: 38\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;My Discr.: 3471785639&nbsp; - Your Discr.: 2432996710\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Min tx interval: 500 &nbsp; - Min rx interval: 500\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Min Echo interval: 500\n</pre><div>&nbsp;</div><p>If BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:</p><pre>switch&gt;show running-config section bfd\nswitch&gt;\n</pre><div>&nbsp;</div><p>If BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:</p><pre>switch&gt;show bfd peers detail\nswitch&gt;\n</pre><div>&nbsp;</div><p>If BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:</p><pre>switch&gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:&nbsp; Version: 1 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Diagnostic: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;State bit: Up&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Demand bit: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Poll bit: 0&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - Final bit: 0\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Multiplier: 20 &nbsp; &nbsp; &nbsp; &nbsp; - Length: 24\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;My Discr.: 3471785639&nbsp; - Your Discr.: 2432996710\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Min tx interval: 500 &nbsp; - Min rx interval: 500\n&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Min Echo interval: 500</pre>"}]}],"workarounds":[{"lang":"en","value":"No mitigation is available for this issue.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>No mitigation is available for this issue.</p>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:\n\n  *  4.36.2F and later releases in the 4.36.x train\n  *  4.35.6M and later releases in the 4.35.x train\n  *  4.34.8M and later releases in the 4.34.x train\n  *  4.33.9M and later releases in the 4.33.x train","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li><li>4.33.9M and later releases in the 4.33.x train</li></ul>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista.","type":"finder"}],"source":{"defect":["1787150"],"advisory":"154","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseSeverity":"HIGH","baseScore":8.2,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.2,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-15T19:38:30.537124Z","id":"CVE-2026-73458","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-15T19:38:38.389Z"}}]}}