Impact
The vulnerability allows an unauthenticated attacker who can reach the layer 2 segment where VRRP is running to bypass VRRP authentication configured using the IP Authentication Header (IP‑AH) method. By forging authentication, the attacker can claim the virtual router’s master role, which permits interception, modification, or discarding of traffic destined for the virtual gateway address. This is a classic authentication bypass flaw (CWE‑303) that can compromise confidentiality, integrity, and availability of communications on the affected network segment.
Affected Systems
The flaw affects Arista Networks EOS platforms, any version prior to the repair releases in the 4.36, 4.35, 4.34, and 4.33 train lines. Specifically, EOS versions before 4.36.2F, before 4.35.6M, before 4.34.8M, and before 4.33.10M are vulnerable. Users must verify the exact EOS version running on their equipment.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying that no known widespread exploits are actively used. However, because the attacker only needs access to the local layer 2 network, the attack can be launched by any unauthenticated host on a VRRP segment, making the potential threat significant for environments not adequately isolated or secured.
OpenCVE Enrichment