{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 173 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24729-security-advisory-0173"
      }
    ],
    "title": "Security Advisory 173",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:22Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 173",
      "initial_release_date": "2026-09-17T11:48:22Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:22Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.0.1",
                    "product": {
                      "name": "EOS version 4.36.0.1",
                      "product_id": "CSAFPID-9"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.5",
                    "product": {
                      "name": "EOS version 4.35.5",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.9",
                    "product": {
                      "name": "EOS version 4.33.9",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.1",
                    "product": {
                      "name": "EOS version 4.36.1",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.8",
                    "product": {
                      "name": "EOS version 4.33.8",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.6",
                    "product": {
                      "name": "EOS version 4.34.6",
                      "product_id": "CSAFPID-7"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.7",
                    "product": {
                      "name": "EOS version 4.34.7",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.4",
                    "product": {
                      "name": "EOS version 4.35.4",
                      "product_id": "CSAFPID-8"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
                "product": {
                  "name": "Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
                  "product_id": "CSAFPID-10"
                }
              }
            ],
            "category": "product_family",
            "name": "Hotfixes"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ],
    "relationships": [
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.34.6 with Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
          "product_id": "CSAFPID-12"
        },
        "product_reference": "CSAFPID-7",
        "relates_to_product_reference": "CSAFPID-10"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.33.8 with Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
          "product_id": "CSAFPID-11"
        },
        "product_reference": "CSAFPID-6",
        "relates_to_product_reference": "CSAFPID-10"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.35.4 with Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
          "product_id": "CSAFPID-13"
        },
        "product_reference": "CSAFPID-8",
        "relates_to_product_reference": "CSAFPID-10"
      },
      {
        "category": "installed_with",
        "full_product_name": {
          "name": "Version 4.36.0.1 with Hotfix SecurityAdvisoryMtNeblina-CVE-2026-73455.swix  ",
          "product_id": "CSAFPID-14"
        },
        "product_reference": "CSAFPID-9",
        "relates_to_product_reference": "CSAFPID-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73455",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1307559"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly. Exploitation of this vulnerability can be executed remotely over the network.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "In order to be vulnerable to CVE-2026-73455, the following condition must be met:\n\nIf OSPFv3 is not configured there is no exposure to this issue and the show command will not produce any output\n\nTo confirm if your configuration is vulnerable, execute the following commands. The vulnerability requires **both** OSPFv3 to be enabled and at least one active neighbor to be present:\n\nNote: If OSPFv3 is not configured, the command will yield no output and your system is not exposed.",
          "title": "1307559: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-2"
        ],
        "first_fixed": [
          "CSAFPID-11",
          "CSAFPID-12",
          "CSAFPID-13",
          "CSAFPID-14"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-3",
          "CSAFPID-4"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73455"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.9",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.7",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.5",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.1",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-2"
          ]
        },
        {
          "category": "mitigation",
          "details": "The OSPFv3 authentication feature helps to mitigate this vulnerability. OSPFv3 authentication prevents unauthorized actors from injecting crafted packets into the OSPF domain. Enabling it on all OSPFv3-speaking interfaces ensures that packets from unauthenticated senders are discarded before they can trigger this vulnerability.\n\n### Per-interface OSPFv3 encryption\n\nConfigure ESP-based encryption with authentication on each OSPFv3 interface. All peers on the same interface must use the same SPI, algorithm, and passphrase.\n\n### Per-area OSPFv3 Configuration:\n\nConfigure ESP-based encryption with authentication on each OSPFv3 area.\n\nCaution: Enabling OSPFv3 authentication must be coordinated across peering neighbors simultaneously. Applying this configuration to a single peer will temporarily break the routing adjacency, resulting in traffic disruption\n\nFor full configuration reference, see the [EOS User Manual \u2014 OSPFv3 Authentication and Encryption.](https://www.arista.com/en/um-eos/eos-open-shortest-path-first-version-3#xx1310548)"
        },
        {
          "category": "mitigation",
          "details": "Hotfix: SecurityAdvisoryMtNeblina-CVE-2026-73455.swix , , Hash: (SHA-512)8f67f7c343bce9b63a62bd359a6bbf6b6cc05cff73aae0a3f8ecefc5bc2f29645448a4b6053ab0bba96eeb6095f1f7529e386d5dbe36fbe0e92f5afa4889dc34",
          "product_ids": [
            "CSAFPID-6",
            "CSAFPID-9",
            "CSAFPID-8",
            "CSAFPID-7"
          ],
          "url": "https://dist.aristanetworks.com/release/patch/CVE-2026-73455/"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-2",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-4",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73455"
    }
  ]
}