{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73444","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:39:35.977Z","datePublished":"2026-09-15T21:11:37.625Z","dateUpdated":"2026-09-16T18:04:45.344Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-15T21:11:37.625Z"},"title":"On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the","datePublic":"2026-09-09T21:09:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-303","description":"CWE-303 Incorrect Implementation of Authentication Algorithm","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-115","descriptions":[{"lang":"en","value":"CAPEC-115 Authentication Bypass"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange","virtual or physical appliance"],"versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","changes":[{"at":"4.36.2F","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","changes":[{"at":"4.35.6M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7M","changes":[{"at":"4.34.8M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"4.33.0","lessThanOrEqual":"4.33.9M","changes":[{"at":"4.33.10M","status":"unaffected"}],"versionType":"custom"},{"status":"affected","version":"0"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.</p>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73444, VRRPv2 must be configured with IP-AH authentication on at least one interface:\n\n\n\nswitch>show running-config section vrrp\ninterface Ethernet1\n   vrrp 1 ipv4 version 2\n   vrrp 1 peer authentication ietf-md5 key-string 7 <key>\n\n\n\nIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure.","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>In order to be vulnerable to CVE-2026-73444, VRRPv2 must be configured with IP-AH authentication on at least one interface:</p><pre>switch&gt;show running-config section vrrp\ninterface Ethernet1\n   vrrp 1 ipv4 version 2\n   vrrp 1 peer authentication ietf-md5 key-string 7 &lt;key&gt;</pre><p>If VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure.</p>"}]}],"workarounds":[{"lang":"en","value":"Restricting physical and logical access to VRRP-enabled segments reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path:\n\n\n\nswitch(config)# interface vlan 20\nswitch(config-if-vl20)# vrrp 1 ipv4 version 3","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>Restricting physical and logical access to VRRP-enabled segments reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path:</p><pre>switch(config)# interface vlan 20\nswitch(config-if-vl20)# vrrp 1 ipv4 version 3</pre>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:\n\n  *  4.36.2F and later releases in the 4.36.x train\n  *  4.35.6M and later releases in the 4.35.x train\n  *  4.34.8M and later releases in the 4.34.x train\n  *  4.33.10M and later releases in the 4.33.x train","supportingMedia":[{"type":"text/html","base64":false,"value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73444 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li><li>4.35.6M and later releases in the 4.35.x train</li><li>4.34.8M and later releases in the 4.34.x train</li><li>4.33.10M and later releases in the 4.33.x train</li></ul>"}]}],"credits":[{"lang":"en","value":"This issue was discovered internally by Arista.","type":"finder"}],"source":{"defect":["1866656"],"advisory":"157","discovery":"INTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":4.7,"vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-16T18:04:26.052032Z","id":"CVE-2026-73444","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T18:04:45.344Z"}}]}}