← All Advisories

Specially Crafted Packet Bypasses BFD Session Authentication on Arista EOS and Takes Down BFD Sessions, Disrupting Dependent Routing Protocols

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-73458

Key Details

CVECVE-2026-73458
CVSS Score / Version8.2 (High) / CVSS v3.1
Updated2026-09-16
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is low; availability impact is high.
Classified asCWE-303 (Incorrect Implementation of Authentication Algorithm)

What to Know

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s). (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-73458
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-73458