CVE-2026-73443
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 ne
CVSS
4.7
Medio
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 16 sept 2026 · Última mod.: 16 sept 2026 · CWE-294
Sin historial EPSS suficiente todavía.
On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is running can capture a legitimate authenticated VRRP advertisement and replay it indefinitely. Replayed advertisements can be used to advertise stale VRRP state, for example to prevent a backup router from taking over the virtual gateway after the original master has gone down, resulting in a denial of service for hosts using the virtual gateway address.