Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73442 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train * 4.33.10M and later releases in the 4.33.x train
Vendor Workaround
If the VRRP feature is not operationally required, disabling it removes the exposure. Otherwise, there is no mitigation or workaround available. Please note that disabling VRRP can lead to network outages if the primary router fails.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arista
Arista eos |
|
| Vendors & Products |
Arista
Arista eos |
Thu, 17 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving forwarded log output) to obtain the peer device VRRP authentication credentials without having access to the network segment on which VRRP is running. | |
| Title | On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a system receiving for | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Arista
Published:
Updated: 2026-09-17T18:32:55.263Z
Reserved: 2026-08-12T16:39:35.977Z
Link: CVE-2026-73442
Updated: 2026-09-17T18:32:37.376Z
Status : Awaiting Analysis
Published: 2026-09-16T19:17:31.080
Modified: 2026-09-17T19:16:56.830
Link: CVE-2026-73442
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:37:05Z
-
CWE-532
Insertion of Sensitive Information into Log File