CVE-2026-73442
published 2026-09-16CVE-2026-73442: On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an…
PriorityP419low3CVSS 3.1
AVAACHPRLUINSCCLINAN
EPSS
0.21%
11.4th percentile
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arista_networks | eos | 4.33.0 – 4.33.9M | — |
| arista_networks | eos | 4.34.0 – 4.34.7M | — |
| arista_networks | eos | 4.35.0 – 4.35.5M | — |
| arista_networks | eos | 4.36.0 – 4.36.1F | — |
CVSS provenance
nvdv3.13.0LOWCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv4.02.1LOWCVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP missing encryption (WID-SEC-2026-3287)
vuldb·2026-09-17·CVSS 3.0
CVE-2026-73442 [LOW] Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F VRRP missing encryption (WID-SEC-2026-3287)
A vulnerability classified as problematic was found in Arista EOS up to 4.33.9M/4.34.7M/4.35.5M/4.36.1F. This affects an unknown function of the component VRRP. Executing a manipulation can lead to missing encryption of sensitive data.
The identification of this vulnerability is CVE-2026-73442. The attack may be launched remotely. There is no exploit available.
GHSA
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privil
ghsa_unreviewed·2026-09-16
CVE-2026-73442 [LOW] CWE-532 On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privil
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-16
Published