cbcvebase.
CVE-2026-73442
published 2026-09-16

CVE-2026-73442: On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an…

PriorityP419low3CVSS 3.1
AVAACHPRLUINSCCLINAN
EPSS
0.21%
11.4th percentile
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.

Affected

4 ranges
VendorProductVersion rangeFixed in
arista_networkseos4.33.0 – 4.33.9M—
arista_networkseos4.34.0 – 4.34.7M—
arista_networkseos4.35.0 – 4.35.5M—
arista_networkseos4.36.0 – 4.36.1F—

CVSS provenance

nvdv3.13.0LOWCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv4.02.1LOWCVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.