CVE-2026-73442 PUBLISHED

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for

Assigner: Arista
Reserved: 12.08.2026 Published: 16.09.2026 Updated: 16.09.2026

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 2.1

Product Status

Vendor Arista Networks
Product EOS
Versions Default: unaffected
  • affected from 4.36.0 to 4.36.1F (incl.)
  • affected from 4.35.0 to 4.35.5M (incl.)
  • affected from 4.34.0 to 4.34.7M (incl.)
  • affected from 4.33.0 to 4.33.9M (incl.)

Affected Configurations

In order to be vulnerable to CVE-2026-73442, VRRP must be configured with either version 2 or version 3:

switch>show running-config section vrrp interface Ethernet1 vrrp 1 ipv4 <ipAddr>

If VRRP is not configured, there is no exposure to CVE-2026-73442.

Workarounds

If the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails.

Solutions

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases:

  • 4.36.2F and later releases in the 4.36.x train
  • 4.35.6M and later releases in the 4.35.x train
  • 4.34.8M and later releases in the 4.34.x train
  • 4.33.10M and later releases in the 4.33.x train

Credits

  • This issue was discovered internally by Arista. finder

References

Problem Types

  • CWE-532 Insertion of Sensitive Information into Log File CWE

Impacts

  • CAPEC-118 Information Disclosure