← Back to CVE List
CVE-2026-73443NVD
Vulnerability Summary
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prevent a backup router from taking over the virtual gateway after the original master has gone down, resulting in a denial of service for hosts using the virtual gateway address.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.7 (MEDIUM)
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- Arista Networks EOS >= 4.36.0 and <= 4.36.1F
- Arista Networks EOS >= 4.35.0 and <= 4.35.5M
- Arista Networks EOS >= 4.34.0 and <= 4.34.7M
- Arista Networks EOS >= 4.33.0 and <= 4.33.9M
- Arista Networks EOS 4.36.1F
- Arista Networks EOS 4.35.5M
- Arista Networks EOS 4.34.7M
- Arista Networks EOS 4.33.9M