CVE-2026-73444: On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the
On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.10M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
Who is exposed to this issue?
Exposure is limited to affected platforms running Arista EOS where VRRPv2 IP Authentication Header (IP-AH) authentication is configured. An attacker must have access to the same Layer 2 network segment on which VRRP is operating.
What does an attacker need to exploit it?
The attacker does not need authentication, user interaction, or prior privileges. They need Layer 2 access to the VRRP segment and can then bypass VRRP authentication to claim the virtual router master role.
What is the practical impact if exploitation succeeds?
A successful attacker can become the virtual router master for the gateway address. This enables interception, modification, or dropping of traffic that segment hosts send to that virtual gateway.