Cleartext VRRP Authentication Exposure in Arista EOS Platforms
CVE-2026-73442

2.1LOW

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73442?

The vulnerability found in platforms running Arista EOS with VRRP enabled exposes peer device VRRP authentication credentials in cleartext. Authenticated users with appropriate privileges can access agent trace logs, potentially allowing them to view sensitive authentication details without needing to be on the same network segment as the VRRP implementation. This poses a significant risk in terms of unauthorized access and exploitation, necessitating prompt patching and vigilance in network security practices.

Affected Version(s)

EOS 710 Series 4.36.0 <= 4.36.1F

EOS 710 Series 4.35.0 <= 4.35.5M

EOS 710 Series 4.34.0 <= 4.34.7M

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered internally by Arista.
.