---
id: CVE-2026-73442
title: >-
  On affected platforms running Arista EOS with VRRP enabled, the peer device
  VRRP authentication credentials are logged in cleartext on the switch,
  allowing an authenticated user with sufficient privileges to view agent trace
  logs (or a s…
summary: >-
  On affected platforms running Arista EOS with VRRP enabled, the peer device
  VRRP authentication credentials are logged in cleartext on the switch,
  allowing an authenticated user with sufficient privileges to view agent trace
  logs (or a s…
severity: low
cvss: 3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-532
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.1F
  - EOS >= 4.35.0 <= 4.35.5M
  - EOS >= 4.34.0 <= 4.34.7M
  - EOS >= 4.33.0 <= 4.33.9M
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:16:56.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73442'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T18:32:32.827325Z'
ingestedAt: '2026-09-16T19:02:30.724Z'
epss: 0.00209
epssPercentile: 0.11431
---

## Overview

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
