{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73442","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:39:35.977Z","datePublished":"2026-09-16T18:50:06.448Z","dateUpdated":"2026-09-17T18:32:55.263Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-16T18:50:06.448Z"},"title":"On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for","datePublic":"2026-09-09T18:48:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-532","description":"CWE-532 Insertion of Sensitive Information into Log File","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-118","descriptions":[{"lang":"en","value":"CAPEC-118 Information Disclosure"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange","virtual or physical appliance"],"versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","changes":[{"at":"4.36.2F","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","changes":[{"at":"4.35.6M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7M","changes":[{"at":"4.34.8M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.33.0","lessThanOrEqual":"4.33.9M","changes":[{"at":"4.33.10M","status":"unaffected"}],"versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73442, VRRP must be configured with either version 2 or version 3:\n\n\n\nswitch>show running-config section vrrp\ninterface Ethernet1\n   vrrp 1 ipv4 <ipAddr>\n\n\n\nIf VRRP is not configured, there is no exposure to CVE-2026-73442.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73442, VRRP must be configured with either version 2 or version 3:</p><pre>switch&gt;show running-config section vrrp\ninterface Ethernet1\n   vrrp 1 ipv4 &lt;ipAddr&gt;</pre><p>If VRRP is not configured, there is no exposure to CVE-2026-73442.</p>"}]}],"workarounds":[{"lang":"en","value":"If the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>If the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails.</p>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases:\n\n  *  4.36.2F and later releases in the 4.36.x train\n  *  4.35.6M and later releases in the 4.35.x train\n  *  4.34.8M and later releases in the 4.34.x train\n  *  4.33.10M and later releases in the 4.33.x train","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li><li>4.33.10M and later releases in the 4.33.x train</li></ul>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista.","type":"finder"}],"source":{"defect":["1857627"],"advisory":"157","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"LOW","baseScore":3,"vectorString":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"LOW","baseScore":2.1,"vectorString":"CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T18:32:32.827325Z","id":"CVE-2026-73442","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T18:32:55.263Z"}}]}}