ZeroHour

CVE-2026-73458

large

Crafted Packet Tears Down Authenticated BFD Sessions on Arista EOS Switches

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73458 is a denial-of-service flaw (CWE-303, incorrect identification of an instance) in Arista EOS platforms where a single specially crafted packet can cause authenticated Bidirectional Forwarding Detection (BFD) sessions to go down, even though the sessions are configured with authentication. An unauthenticated, network-adjacent (or on-path) attacker who can deliver a crafted packet to the device does not need valid BFD credentials to force the session to fail, and the CVSS 4.0 score of 9.2 reflects the high availability impact. Because routing protocols such as BGP, OSPF and IS-IS commonly use BFD for fast failure detection, killing BFD sessions can trigger route withdrawals, reconvergence or blackholing, producing undesirable network changes and outages. Any organization running an affected EOS release on affected platforms with authenticated BFD sessions configured is exposed, particularly data centers, service provider and enterprise core networks where BFD is widely deployed. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and no in-the-wild exploitation has been reported.

What to do: Patch affected platforms to the fixed EOS release listed in the Arista security advisory ([email protected] is the CNA — consult the advisory for exact version numbers). Until patched, restrict who can reach BFD by applying infrastructure ACLs, control-plane policing (CoPP) and TTL/GTSM-style hop-limit enforcement on BFD peers, and treat BFD session flaps without a corresponding link-down event as a possible indicator of crafted-packet attacks. Verify after upgrade that authenticated BFD sessions remain stable and that routing-protocol dampening limits blast radius from a single session loss.

Affected
Arista EOS (Extensible Operating System)
Estimated exposure
large≈ hundreds of thousands of Arista EOS switches deployed enterprise-wide, with an unknown subset running authenticated BFD sessions — Arista's cumulative switch installed base (millions of ports across 10,000+ customers per public financial disclosures) and public internet scans showing tens of thousands of internet-reachable Arista devices, though most BFD exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).

Weakness
CWE-303
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.