← Back to CVE List
CVE-2026-73442NVD
Vulnerability Summary
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
CVSS v4.0 Base Metrics — Score 2.1 (LOW)
Attack VectorAdjacent
Attack ComplexityHigh
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)Low
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 3.0 (LOW)
Attack VectorAdjacent
Attack ComplexityHigh
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityLow
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Arista Networks EOS >= 4.36.0 and <= 4.36.1F
- Arista Networks EOS >= 4.35.0 and <= 4.35.5M
- Arista Networks EOS >= 4.34.0 and <= 4.34.7M
- Arista Networks EOS >= 4.33.0 and <= 4.33.9M
- Arista Networks EOS 4.36.1F
- Arista Networks EOS 4.35.5M
- Arista Networks EOS 4.34.7M
- Arista Networks EOS 4.33.9M