Junglewise Threat Intelligence

CVE-2026-73444: Arista EOS VRRPv2 authentication bypass via IP-AH

CVE-2026-73444 · Severity: medium · CVSS 4.7 · Published 2026-09-15

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS is networking software that manages virtual router redundancy across network switches. A vulnerability in VRRPv2 IP Authentication Header (IP-AH) authentication allows an attacker on the same network segment to bypass authentication and take control of the virtual router, enabling interception and redirection of traffic intended for the virtual gateway address.

Technical details

The vulnerability is an incorrect implementation of the VRRPv2 IP-AH authentication algorithm (CWE-303). An unauthenticated attacker with layer 2 network access can forge or manipulate VRRP advertisements to bypass the authentication check and claim the virtual router master role. The attack requires the target to have VRRPv2 enabled with IP-AH authentication explicitly configured (not the default); VRRPv3 and unauthenticated VRRPv2 deployments are unaffected. Successful exploitation allows the attacker to intercept, modify, or discard traffic destined for the virtual gateway, resulting in denial of service or man-in-the-middle attacks. Patches are available for affected EOS versions 4.36.1F and below in the 4.36.x train, 4.35.5M and below in 4.35.x, 4.34.7M and below in 4.34.x, and 4.33.9M and below in 4.33.x.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x train), 4.35.5M and below (4.35.x train), 4.34.7M and below (4.34.x train), 4.33.9M and below (4.33.x train), and all prior releases

Timeline

  • 2026-09-15: disclosed
  • 2026-09-09: advisory: Arista Security Advisory 0157 released

References

Related threats