Junglewise Threat Intelligence

CVE-2026-73442: Arista EOS VRRP credentials in cleartext logs

CVE-2026-73442 · Severity: low · CVSS 3 · Published 2026-09-16

Executive brief

Arista EOS network switches log VRRP peer authentication credentials in plaintext within internal agent trace logs. An authenticated user with log access privileges, or any system receiving forwarded logs, can extract these credentials without network access, potentially compromising VRRP authentication across multiple devices and enabling gateway hijacking or traffic interception.

Technical details

This is an information disclosure vulnerability (CWE-532: Insertion of Sensitive Information into Log File) affecting Arista EOS when VRRP is enabled. The root cause is improper log filtering that allows VRRP authentication credentials to be written in cleartext to agent trace logs. The attack vector is adjacent (requires local/authenticated access to view logs or receive forwarded log output), and requires the attacker to have sufficient privileges on the switch. Once obtained, credentials can be used to authenticate malicious VRRP messages and assume master role. Patches are available in EOS 4.36.2 and later, 4.35.6M and later, 4.34.8M and later, and 4.33.10M and later.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x train), 4.35.5M and below (4.35.x train), 4.34.7M and below (4.34.x train), 4.33.9M and below (4.33.x train), and all prior releases

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0157 initial release
  • 2026-09-16: advisory: NVD published CVE-2026-73442

References

Related threats