Vulnerability in Arista EOS with VRRPv2 Authentication Affecting Network Functions
CVE-2026-73443
5.3MEDIUM
What is CVE-2026-73443?
A vulnerability exists in Arista EOS when VRRPv2 IP-AH authentication is enabled. An unauthenticated attacker on the same Layer 2 network segment can exploit this flaw by capturing legitimate VRRP advertisements. This allows the attacker to replay these advertisements indefinitely, which can disrupt the normal functioning of the network. By advertising stale VRRP state, the attacker can prevent the backup router from assuming control of the virtual gateway once the original master router fails. Consequently, this situation can lead to denial of service for users relying on the virtual gateway address.
Affected Version(s)
EOS 710 Series 4.36.0 <= 4.36.1F
EOS 710 Series 4.35.0 <= 4.35.5M
EOS 710 Series 4.34.0 <= 4.34.7M
