{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 171 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24727-security-advisory-0171"
      }
    ],
    "title": "Security Advisory 171",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:21Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 171",
      "initial_release_date": "2026-09-17T11:48:21Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:21Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7.1",
                    "product": {
                      "name": "EOS version 4.34.7.1",
                      "product_id": "CSAFPID-5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.5",
                    "product": {
                      "name": "EOS version 4.35.5",
                      "product_id": "CSAFPID-9"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.31.1",
                    "product": {
                      "name": "EOS version 4.31.1",
                      "product_id": "CSAFPID-16"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.10",
                    "product": {
                      "name": "EOS version 4.33.10",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7",
                    "product": {
                      "name": "EOS version 4.34.7",
                      "product_id": "CSAFPID-8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-7"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-10"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
                "product": {
                  "name": "Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
                  "product_id": "CSAFPID-11"
                }
              }
            ],
            "category": "product_family",
            "name": "Hotfixes"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ],
    "relationships": [
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.33.9 with Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
          "product_id": "CSAFPID-12"
        },
        "product_reference": "CSAFPID-7",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.36.1 with Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
          "product_id": "CSAFPID-15"
        },
        "product_reference": "CSAFPID-10",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.34.7 with Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
          "product_id": "CSAFPID-13"
        },
        "product_reference": "CSAFPID-8",
        "relates_to_product_reference": "CSAFPID-11"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.35.5 with Hotfix SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix 1.0",
          "product_id": "CSAFPID-14"
        },
        "product_reference": "CSAFPID-9",
        "relates_to_product_reference": "CSAFPID-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73435",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1843809"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafted OSPFv2 packet from an unauthenticated attacker on the same broadcast segment, with OSPFv2 authentication configured can cause adjacency flapping and packet loss. The disruption can affect routing across the broader OSPF domain.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "CVE-2026-73435\n\nIn order to be vulnerable to CVE-2026-73435, all of the following conditions must be met:\n\n1. The vulnerable OSPFv2 instance must have at least two neighbors on the same interface.\n2. The interface is a broadcast interface. \n3. OSPFv2 cryptographic authentication is configured.\n\nHere is an example showing a vulnerable OSPFv2 instance with a minimum of two neighbors on the same interface.\n\nHere is an example showing the vulnerable configuration of Network Type \u201cBroadcast\u201d and Message-digest authentication (cryptographic authentication) configured:\n\nNote: Both \u201cMessage-digest authentication\u201d ( MD5 ) and \u201cMessage-digest sha<X> authentication\u201d ( SHA ) are vulnerable.\n\nTo check area-level authentication, reference the vulnerable interface area ID in `\u201c``show ip ospf\u201d` output below:\n\nIf the area has \u201c`Simple`\u201d or \u201c`None`\u201d authentication, then at the area-level, the third prerequisite is unmet and the system would not be vulnerable to this particular issue.\n\nCVE-2026-73436\n\nIn order to be vulnerable to CVE-2026-73436, the following condition must be met:\n\nOSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.\n\nIf OSPFv2 segment routing is not configured, then there is no exposure to this issue.",
          "title": "1843809: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-4"
        ],
        "first_fixed": [
          "CSAFPID-12",
          "CSAFPID-13",
          "CSAFPID-14",
          "CSAFPID-15"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-3",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73435",
          "summary": "MITRE"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7.1",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "mitigation",
          "details": "Hotfix: SecurityAdvisoryMtCopahueHotfix-CVE-2026-73435.swix, 1.0, Hash: (SHA-512)4c4ff053d8165f347b45dfcafc2d20396e3eb00869b0088f3128be7f53b2a028b479fa8279849c800b5916ab9aaf8077718a68e3bf4277d55b44076650de0aa7",
          "product_ids": [
            "CSAFPID-9",
            "CSAFPID-8",
            "CSAFPID-7",
            "CSAFPID-10"
          ],
          "url": "https://dist.aristanetworks.com/release/patch/CVE-2026-73435/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73435"
    },
    {
      "cve": "CVE-2026-73436",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1843812"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 packet from an adjacent OSPF neighbor may cause OSPF to restart unexpectedly.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "CVE-2026-73435\n\nIn order to be vulnerable to CVE-2026-73435, all of the following conditions must be met:\n\n1. The vulnerable OSPFv2 instance must have at least two neighbors on the same interface.\n2. The interface is a broadcast interface. \n3. OSPFv2 cryptographic authentication is configured.\n\nHere is an example showing a vulnerable OSPFv2 instance with a minimum of two neighbors on the same interface.\n\nHere is an example showing the vulnerable configuration of Network Type \u201cBroadcast\u201d and Message-digest authentication (cryptographic authentication) configured:\n\nNote: Both \u201cMessage-digest authentication\u201d ( MD5 ) and \u201cMessage-digest sha<X> authentication\u201d ( SHA ) are vulnerable.\n\nTo check area-level authentication, reference the vulnerable interface area ID in `\u201c``show ip ospf\u201d` output below:\n\nIf the area has \u201c`Simple`\u201d or \u201c`None`\u201d authentication, then at the area-level, the third prerequisite is unmet and the system would not be vulnerable to this particular issue.\n\nCVE-2026-73436\n\nIn order to be vulnerable to CVE-2026-73436, the following condition must be met:\n\nOSPFv2 segment routing must be configured. If the below command shows any OSPF instance, then the deployment is vulnerable.\n\nIf OSPFv2 segment routing is not configured, then there is no exposure to this issue.",
          "title": "1843812: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-16"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-2",
          "CSAFPID-3"
        ]
      },
      "references": [
        {
          "category": "external",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73436",
          "summary": "MITRE"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.31.1",
          "product_ids": [
            "CSAFPID-16"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-16",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73436"
    }
  ]
}