Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The following EOS releases contain the fix: - 4.33.9M and later in the 4.33.x train - 4.34.7M and later in the 4.34.x train - 4.35.5M and later in the 4.35.x train - 4.36.1F and later in the 4.36.x train A hotfix (version 1.0) is available for 4.36.0.1F, 4.35.4M, 4.34.6M, and 4.33.8M.
Vendor Workaround
Configure OSPFv3 IPsec encryption to authenticate/encrypt OSPFv3 packets. Per-interface encryption: switch(config)# interface <interface-name> switch(config-if)# ospfv3 encryption ipsec spi <spi-value> esp aes-256-cbc sha1 passphrase <shared-passphrase> Per-area encryption: switch(config)# router ospfv3 switch(config-router-ospfv3)# address-family ipv4 switch(config-router-ospfv3-af)# area <area-id> encryption ipsec spi <spi-value> esp aes-256-cbc sha1 passphrase <shared-passphrase>
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly. | |
| Title | Security Advisory 0173 | |
| Weaknesses | CWE-130 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-16T09:46:15.888Z
Reserved: 2026-08-12T16:45:03.510Z
Link: CVE-2026-73455
No data.
Status : Received
Published: 2026-09-16T10:16:52.243
Modified: 2026-09-16T10:16:52.243
Link: CVE-2026-73455
No data.
OpenCVE Enrichment
No data.