Description
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prevent a backup router from taking over the virtual gateway after the original master has gone down, resulting in a denial of service for hosts using the virtual gateway address.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via VRRP advertisement replay
Action: Patch & Enable
AI Analysis

Impact

A flaw in Arista EOS allows an unauthenticated insider on the same layer‑2 segment to capture a valid VRRPv2 IP‑AH advertisement and replay it indefinitely. The attacker can force routers to believe a stale master still exists, preventing a backup router from assuming the virtual gateway address. This results in a denial of service for hosts that rely on the failed virtual gateway and exploits the authentication weakness identified by CWE‑294.

Affected Systems

The vulnerability affects all Arista EOS releases older than EOS 4.36.2F, 4.35.6M, 4.34.8M, and 4.33.10M when VRRPv2 IP‑AH authentication is enabled. It applies to EOS‑based platforms running VRRP on any VLAN with IP‑AH authentication active.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a low probability of exploitation. The attack requires physical or logical access to the same layer‑2 network segment where VRRP operates, and it is not listed in the CISA KEV catalog. Although the vulnerability can cause a persistent DoS, it is mitigated by software upgrades that introduce explicit replay protection, which must be enabled manually after the upgrade.

Generated by OpenCVE AI on September 18, 2026 at 01:03 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Important: Upgrading alone is not sufficient. The replay protection introduced by the fix is disabled by default and must be explicitly enabled with the following new global configuration command after upgrading to a remediated release: switch(config)#vrrp ipv4 authentication anti-replay CVE-2026-73443 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train * 4.33.10M and later releases in the 4.33.x train


Vendor Workaround

Exposure is limited to attackers with access to the layer 2 network segment on which VRRP is running. Restricting physical and logical access to VRRP-enabled segments (for example with port security and by not extending VRRP VLANs to untrusted access ports) reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path. The below configuration shows how to configure VRRPv3 on VLAN 20: switch(config)# interface vlan 20 switch(config-if-vl20)# vrrp 1 ipv4 version 3


OpenCVE Recommended Actions

  • Upgrade to EOS 4.36.2F or later, 4.35.6M or later, 4.34.8M or later, or 4.33.10M or later.
  • Enable VRRP replay protection by configuring the global command ‘vrrp ipv4 authentication anti-replay’ on the upgraded device.
  • Limit layer‑2 exposure to VRRP segments by implementing port security, restricting VLAN propagation to untrusted ports, or migrating to VRRPv3 and reconfiguring the VLAN accordingly.

Generated by OpenCVE AI on September 18, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prevent a backup router from taking over the virtual gateway after the original master has gone down, resulting in a denial of service for hosts using the virtual gateway address.
Title On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indef
Weaknesses CWE-294
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T18:33:52.236Z

Reserved: 2026-08-12T16:39:35.977Z

Link: CVE-2026-73443

cve-icon Vulnrichment

Updated: 2026-09-17T18:33:43.960Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:31.330

Modified: 2026-09-17T19:16:57.003

Link: CVE-2026-73443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:14Z

Weaknesses
  • CWE-294

    Authentication Bypass by Capture-replay