Executive brief
Arista EOS switches running VRRP version 2 with IP-AH authentication are vulnerable to replay attacks. An attacker on the same local network can capture and repeatedly resend legitimate VRRP messages to prevent failover between redundant routers, causing network outages for hosts relying on the virtual gateway. This affects organizations using Arista switches for network redundancy.
Technical details
The vulnerability is a capture-replay attack (CWE-294) in VRRPv2 IP-AH authentication on Arista EOS. An unauthenticated attacker with layer 2 access to the VRRP network segment can capture legitimate authenticated VRRP advertisements and replay them indefinitely without the ability to forge new messages. By replaying stale advertisements from the master router, the attacker prevents a backup router from taking over when the master fails, resulting in denial of service. The attack requires VRRPv2 (the default version) and IP-AH authentication to be explicitly configured. VRRPv3 or VRRPv2 without authentication are not affected. Patches are available in fixed EOS versions (4.36.2F and later in the 4.36.x train, and corresponding fixes in 4.35.x, 4.34.x, and 4.33.x trains).
Affected products
- Arista EOS 4.36.1F and below (4.36.x train); 4.35.5M and below (4.35.x train); 4.34.7M and below (4.34.x train); 4.33.9M and below (4.33.x train); and all prior releases
Timeline
- 2026-09-16: disclosed: CVE-2026-73443 published in NVD
- 2026-09-09: advisory: Arista Security Advisory 0157 released (initial revision 1.0)