{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 157 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24713-security-advisory-0157"
      }
    ],
    "title": "Security Advisory 157",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:13Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 157",
      "initial_release_date": "2026-09-17T11:48:13Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:13Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.10",
                    "product": {
                      "name": "EOS version 4.33.10",
                      "product_id": "CSAFPID-5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73443",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1866651"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prevent a backup router from taking over the virtual gateway after the original master has gone down, resulting in a denial of service for hosts using the virtual gateway address.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73444 and CVE-2026-73443\n\nIn order to be vulnerable to CVE-2026-73444 or CVE-2026-73443, the following condition must be met:\n\nVRRPv2 must be configured with IP-AH authentication on at least one interface (a vulnerable configuration shows a virtual router with version 2 (the default version) and IP-AH authentication):\n\nIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure to the above two CVEs.\n\n#### CVE-2026-73442\n\nIn order to be vulnerable to CVE-2026-73442, the following condition must be met:\n\n1. VRRP must be configured with either version 2 or version3:\n\nIf VRRP is not configured, there is no exposure to CVE-2026-73442.",
          "title": "1866651: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73443"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "### CVE-2026-73444 and CVE-2026-73443\n\nExposure is limited to attackers with access to the layer 2 network segment on which VRRP is running. Restricting physical and logical access to VRRP-enabled segments (for example with port security and by not extending VRRP VLANs to untrusted access ports) reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path.\n\nThe below configuration shows how to configure VRRPv3 on VLAN 20:\n\n### CVE-2026-73442\n\nIf the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73443"
    },
    {
      "cve": "CVE-2026-73444",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1866656"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment on which VRRP is running could bypass VRRP authentication and claim the virtual router master role, enabling the attacker to intercept, modify, or discard traffic that hosts on the segment send to the virtual gateway address.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73444 and CVE-2026-73443\n\nIn order to be vulnerable to CVE-2026-73444 or CVE-2026-73443, the following condition must be met:\n\nVRRPv2 must be configured with IP-AH authentication on at least one interface (a vulnerable configuration shows a virtual router with version 2 (the default version) and IP-AH authentication):\n\nIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure to the above two CVEs.\n\n#### CVE-2026-73442\n\nIn order to be vulnerable to CVE-2026-73442, the following condition must be met:\n\n1. VRRP must be configured with either version 2 or version3:\n\nIf VRRP is not configured, there is no exposure to CVE-2026-73442.",
          "title": "1866656: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73444"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "### CVE-2026-73444 and CVE-2026-73443\n\nExposure is limited to attackers with access to the layer 2 network segment on which VRRP is running. Restricting physical and logical access to VRRP-enabled segments (for example with port security and by not extending VRRP VLANs to untrusted access ports) reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path.\n\nThe below configuration shows how to configure VRRPv3 on VLAN 20:\n\n### CVE-2026-73442\n\nIf the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73444"
    },
    {
      "cve": "CVE-2026-73442",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1857627"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73444 and CVE-2026-73443\n\nIn order to be vulnerable to CVE-2026-73444 or CVE-2026-73443, the following condition must be met:\n\nVRRPv2 must be configured with IP-AH authentication on at least one interface (a vulnerable configuration shows a virtual router with version 2 (the default version) and IP-AH authentication):\n\nIf VRRP is not configured, or is configured as version 3, or is configured without authentication, there is no exposure to the above two CVEs.\n\n#### CVE-2026-73442\n\nIn order to be vulnerable to CVE-2026-73442, the following condition must be met:\n\n1. VRRP must be configured with either version 2 or version3:\n\nIf VRRP is not configured, there is no exposure to CVE-2026-73442.",
          "title": "1857627: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73442"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "### CVE-2026-73444 and CVE-2026-73443\n\nExposure is limited to attackers with access to the layer 2 network segment on which VRRP is running. Restricting physical and logical access to VRRP-enabled segments (for example with port security and by not extending VRRP VLANs to untrusted access ports) reduces the attack surface. Additionally, migrating virtual routers from VRRP version 2 with authentication to VRRP version 3 removes the vulnerable code path.\n\nThe below configuration shows how to configure VRRPv3 on VLAN 20:\n\n### CVE-2026-73442\n\nIf the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails."
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.0,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73442"
    }
  ]
}