CVE-2026-73458
largeCrafted Packet Tears Down Authenticated BFD Sessions on Arista EOS Switches
CVE-2026-73458 is a denial-of-service flaw (CWE-303, incorrect identification of an instance) in Arista EOS platforms where a single specially crafted packet can cause authenticated Bidirectional Forwarding Detection (BFD) sessions to go down, even though the sessions are configured with authentication. An unauthenticated, network-adjacent (or on-path) attacker who can deliver a crafted packet to the device does not need valid BFD credentials to force the session to fail, and the CVSS 4.0 score of 9.2 reflects the high availability impact. Because routing protocols such as BGP, OSPF and IS-IS commonly use BFD for fast failure detection, killing BFD sessions can trigger route withdrawals, reconvergence or blackholing, producing undesirable network changes and outages. Any organization running an affected EOS release on affected platforms with authenticated BFD sessions configured is exposed, particularly data centers, service provider and enterprise core networks where BFD is widely deployed. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation has been reported.
What to do: Patch affected platforms to the fixed EOS release listed in the Arista security advisory ([email protected] is the CNA — consult the advisory for exact version numbers). Until patched, restrict who can reach BFD by applying infrastructure ACLs, control-plane policing (CoPP) and TTL/GTSM-style hop-limit enforcement on BFD peers, and treat BFD session flaps without a corresponding link-down event as a possible indicator of crafted-packet attacks. Verify after upgrade that authenticated BFD sessions remain stable and that routing-protocol dampening limits blast radius from a single session loss.
| Arista EOS (Extensible Operating System) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).
- Weakness
- CWE-303
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.