Skip to content
arista-networksCVE-2026-73442

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient...

Low2.1CVE-2026-73442 · Published Sep 16, 2026 · updated Sep 17, 2026

Source advisory

Affected versions

PackageAffectedFixed in
EOS
Vendor
>= 4.36.0, <= 4.36.1FNo fix yet
>= 4.35.0, <= 4.35.5MNo fix yet
>= 4.34.0, <= 4.34.7MNo fix yet
>= 4.33.0, <= 4.33.9MNo fix yet
Details and references

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.

CVSS 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
no source yet
Weakness
CWE-532

More arista-networks advisories

All
DateAdvisory
Sep 16On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to...
CVE-2026-73446High7.0no fix yet
Sep 16On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged...
CVE-2026-73459High7.0no fix yet
Sep 16On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart...
CVE-2026-73460High7.0no fix yet
Sep 15On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from...
CVE-2026-73437Medium6.5no fix yet
Sep 15On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP...
CVE-2026-73444Medium5.3no fix yet
Sep 15On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with...
CVE-2026-19655High7.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.