Impact
On Arista EOS platforms configured with VRRP, the switch logs the peer device VRRP authentication password in plain text. An authenticated user with sufficient privileges can read agent trace logs or forwarded log output, thereby obtaining the hidden credentials without needing network access to the VRRP segment. This leakage exposes the authentication secrets that could be used to impersonate the peer router, potentially compromising routing decisions and disrupting network availability. The CVSS score of 2.1 indicates a low severity impact within the scope of privileged users but still represents a clear disclosure risk.
Affected Systems
This issue is present on Arista Networks EOS firmware versions within the 4.33.x, 4.34.x, 4.35.x, and 4.36.x trains. The vulnerability is fixed in version 4.36.2F and later, 4.35.6M and later, 4.34.8M and later, and 4.33.10M and later releases of each respective train.
Risk and Exploitability
The attack vector requires authenticated, privileged access to the switch; the EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the disclosure occurs via local log access, the risk is confined to users who can read manager or trace logs; an attacker would still need the necessary credentials to modify or enable VRRP. Disabling VRRP eliminates the exposure entirely but may affect failover services. Overall, the risk level remains low, but the confidentiality of VRRP credentials is compromised for privileged users.
OpenCVE Enrichment