Description
On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
Published: 2026-09-16
Score: 2.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of VRRP authentication credentials
Action: Patch
AI Analysis

Impact

On Arista EOS platforms configured with VRRP, the switch logs the peer device VRRP authentication password in plain text. An authenticated user with sufficient privileges can read agent trace logs or forwarded log output, thereby obtaining the hidden credentials without needing network access to the VRRP segment. This leakage exposes the authentication secrets that could be used to impersonate the peer router, potentially compromising routing decisions and disrupting network availability. The CVSS score of 2.1 indicates a low severity impact within the scope of privileged users but still represents a clear disclosure risk.

Affected Systems

This issue is present on Arista Networks EOS firmware versions within the 4.33.x, 4.34.x, 4.35.x, and 4.36.x trains. The vulnerability is fixed in version 4.36.2F and later, 4.35.6M and later, 4.34.8M and later, and 4.33.10M and later releases of each respective train.

Risk and Exploitability

The attack vector requires authenticated, privileged access to the switch; the EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the disclosure occurs via local log access, the risk is confined to users who can read manager or trace logs; an attacker would still need the necessary credentials to modify or enable VRRP. Disabling VRRP eliminates the exposure entirely but may affect failover services. Overall, the risk level remains low, but the confidentiality of VRRP credentials is compromised for privileged users.

Generated by OpenCVE AI on September 18, 2026 at 01:03 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train * 4.33.10M and later releases in the 4.33.x train


Vendor Workaround

If the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails.


OpenCVE Recommended Actions

  • Upgrade Arista EOS to any version that includes the fix (4.36.2F or later, 4.35.6M or later, 4.34.8M or later, or 4.33.10M or later).
  • If VRRP is not essential for failover, disable the VRRP feature to eliminate the credential logging risk; otherwise, no alternative mitigation is available.
  • Restrict access to agent trace logs so that only authorized personnel can view them, and consider configuring logging to exclude sensitive credentials when possible.

Generated by OpenCVE AI on September 18, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.
Title On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T18:32:55.263Z

Reserved: 2026-08-12T16:39:35.977Z

Link: CVE-2026-73442

cve-icon Vulnrichment

Updated: 2026-09-17T18:32:37.376Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:31.080

Modified: 2026-09-17T19:16:56.830

Link: CVE-2026-73442

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:05Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File