GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: VRRPv2 IP-AH authentication bypass lets an attacker claim the virtual router master role

CVSS 5.3CVE-2026-73444Firmware, BMC & network fabriccurated

Impact

VRRPv2 authentication using IP-AH can be bypassed, so an unauthenticated attacker on the VRRP layer 2 segment can take the master role for the virtual gateway address. Every host on that segment then sends its default-gateway traffic to the attacker, who can intercept, modify or drop it. Where a GPU cluster's storage, management or egress path runs through a VRRP gateway, this is a position on the wire for the whole segment, and it holds until the legitimate master is restored. The record's CVSS reflects availability only, but the description explicitly covers interception and modification.

Who can reach it

Unauthenticated attacker with access to the layer 2 segment on which VRRP runs. Any compromised host or tenant device on that VLAN qualifies; no switch credentials are needed.

What to do

Upgrade to the fixed EOS release or hotfix in Arista security advisory 0157 - the record does not name a fixed version. Treat IP-AH authentication as not providing the protection it appears to until patched, and keep VRRP segments off networks that untrusted hosts can reach. Rolling the fix means a switch maintenance window per gateway pair.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.