Impact
A flaw in Arista EOS allows an unauthenticated insider on the same layer‑2 segment to capture a valid VRRPv2 IP‑AH advertisement and replay it indefinitely. The attacker can force routers to believe a stale master still exists, preventing a backup router from assuming the virtual gateway address. This results in a denial of service for hosts that rely on the failed virtual gateway and exploits the authentication weakness identified by CWE‑294.
Affected Systems
The vulnerability affects all Arista EOS releases older than EOS 4.36.2F, 4.35.6M, 4.34.8M, and 4.33.10M when VRRPv2 IP‑AH authentication is enabled. It applies to EOS‑based platforms running VRRP on any VLAN with IP‑AH authentication active.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation. The attack requires physical or logical access to the same layer‑2 network segment where VRRP operates, and it is not listed in the CISA KEV catalog. Although the vulnerability can cause a persistent DoS, it is mitigated by software upgrades that introduce explicit replay protection, which must be enabled manually after the upgrade.
OpenCVE Enrichment