Vulnerability in Arista EOS with VRRPv2 Authentication Affecting Network Functions
CVE-2026-73443

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73443?

A vulnerability exists in Arista EOS when VRRPv2 IP-AH authentication is enabled. An unauthenticated attacker on the same Layer 2 network segment can exploit this flaw by capturing legitimate VRRP advertisements. This allows the attacker to replay these advertisements indefinitely, which can disrupt the normal functioning of the network. By advertising stale VRRP state, the attacker can prevent the backup router from assuming control of the virtual gateway once the original master router fails. Consequently, this situation can lead to denial of service for users relying on the virtual gateway address.

Affected Version(s)

EOS 710 Series 4.36.0 <= 4.36.1F

EOS 710 Series 4.35.0 <= 4.35.5M

EOS 710 Series 4.34.0 <= 4.34.7M

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.