Action not permitted
Modal body text goes here.
Modal Title
Modal Body
WID-SEC-W-2026-3410
Vulnerability from csaf_certbund - Published: 2026-09-15 22:00 - Updated: 2026-09-15 22:00Summary
Arista EOS: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: Arista Extensible Operating System (EOS) ist ein modulares Linux basiertes Netzwerkbetriebssystem.
Angriff: Ein Angreifer kann mehrere Schwachstellen in Arista EOS ausnutzen, um sensible Schlüssel, Passwörter oder TACACS+-Secrets offenzulegen, Sicherheits- und Zugriffskontrollen zu beeinträchtigen, Netzwerk- oder Authentifizierungsdienste zu stören, Benutzerkonten mit erhöhten Berechtigungen auszustatten und im schwerwiegendsten Fall beliebigen Code mit Root-Rechten auf dem betroffenen Switch auszuführen.
Betroffene Betriebssysteme: - Sonstiges
Affected products
Known affected
4 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Arista EOS <4.34.8M
Arista / EOS
|
<4.34.8M | ||
|
Arista EOS <4.33.10M
Arista / EOS
|
<4.33.10M | ||
|
Arista EOS <4.36.2F
Arista / EOS
|
<4.36.2F | ||
|
Arista EOS <4.35.6M
Arista / EOS
|
<4.35.6M |
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
Affected products
Known affected
4 products, the same list as for
CVE-2026-19641
References
9 references
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "Arista Extensible Operating System (EOS) ist ein modulares Linux basiertes Netzwerkbetriebssystem.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in Arista EOS ausnutzen, um sensible Schl\u00fcssel, Passw\u00f6rter oder TACACS+-Secrets offenzulegen, Sicherheits- und Zugriffskontrollen zu beeintr\u00e4chtigen, Netzwerk- oder Authentifizierungsdienste zu st\u00f6ren, Benutzerkonten mit erh\u00f6hten Berechtigungen auszustatten und im schwerwiegendsten Fall beliebigen Code mit Root-Rechten auf dem betroffenen Switch auszuf\u00fchren.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Sonstiges",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3410 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3410.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3410 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3410"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24721-security-advisory-0165"
},
{
"category": "external",
"summary": "Arista Security Advisory vom 2026-09-15",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24722-security-advisory-0166"
}
],
"source_lang": "en-US",
"title": "Arista EOS: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-15T22:00:00.000+00:00",
"generator": {
"date": "2026-09-16T11:36:32.921+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3410",
"initial_release_date": "2026-09-15T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-15T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
}
],
"status": "final",
"version": "1"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "\u003c4.35.6M",
"product": {
"name": "Arista EOS \u003c4.35.6M",
"product_id": "T059359"
}
},
{
"category": "product_version",
"name": "4.35.6M",
"product": {
"name": "Arista EOS 4.35.6M",
"product_id": "T059359-fixed",
"product_identification_helper": {
"cpe": "cpe:/o:arista:arista_eos:4.35.6m"
}
}
},
{
"category": "product_version_range",
"name": "\u003c4.34.8M",
"product": {
"name": "Arista EOS \u003c4.34.8M",
"product_id": "T059360"
}
},
{
"category": "product_version",
"name": "4.34.8M",
"product": {
"name": "Arista EOS 4.34.8M",
"product_id": "T059360-fixed",
"product_identification_helper": {
"cpe": "cpe:/o:arista:arista_eos:4.34.8m"
}
}
},
{
"category": "product_version_range",
"name": "\u003c4.36.2F",
"product": {
"name": "Arista EOS \u003c4.36.2F",
"product_id": "T059361"
}
},
{
"category": "product_version",
"name": "4.36.2F",
"product": {
"name": "Arista EOS 4.36.2F",
"product_id": "T059361-fixed",
"product_identification_helper": {
"cpe": "cpe:/o:arista:arista_eos:4.36.2f"
}
}
},
{
"category": "product_version_range",
"name": "\u003c4.33.10M",
"product": {
"name": "Arista EOS \u003c4.33.10M",
"product_id": "T059362"
}
},
{
"category": "product_version",
"name": "4.33.10M",
"product": {
"name": "Arista EOS 4.33.10M",
"product_id": "T059362-fixed",
"product_identification_helper": {
"cpe": "cpe:/o:arista:arista_eos:4.33.10m"
}
}
}
],
"category": "product_name",
"name": "EOS"
}
],
"category": "vendor",
"name": "Arista"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-19641",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-19641"
},
{
"cve": "CVE-2026-73451",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73451"
},
{
"cve": "CVE-2026-73454",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73454"
},
{
"cve": "CVE-2026-73458",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73458"
},
{
"cve": "CVE-2026-73464",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73464"
},
{
"cve": "CVE-2026-73465",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73465"
},
{
"cve": "CVE-2026-73466",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73466"
},
{
"cve": "CVE-2026-73467",
"product_status": {
"known_affected": [
"T059360",
"T059362",
"T059361",
"T059359"
]
},
"release_date": "2026-09-15T22:00:00.000+00:00",
"title": "CVE-2026-73467"
}
]
}
CVE-2026-19641 (GCVE-0-2026-19641)
Vulnerability from cvelistv5 – Published: 2026-09-15 18:17 – Updated: 2026-09-15 19:25
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Summary
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 19:24 UTC
CWE
- CWE-116 - Improper Encoding or Escaping
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.0F
(custom)
Affected: 4.35.0 , ≤ 4.35.5M (custom) Affected: 4.34.0 , ≤ 4.34.7.1M (custom) Affected: 0.0.0 , ≤ 4.33.8M (custom) |
Date Public
2026-09-09 18:15
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19641",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:24:56.712841Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:25:06.761Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "4.36.0F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7.1M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "0.0.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eIn order to be vulnerable to CVE-2026-19641, both of the following conditions must be met:\u003c/p\u003e\u003col\u003e\u003cli\u003eLogin authentication must be enabled, which is the default configuration.\u003cbr\u003eThe following command can be used to verify the login authentication methods.\u003cbr\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cpre\u003eswitch\u0026gt;show aaa methods authentication\u0026nbsp;\nAuthentication method lists for LOGIN:\n\u0026nbsp;\u0026nbsp;name=default methods=local\nAuthentication method list for ENABLE:\n\u0026nbsp;\u0026nbsp;name=default methods=local\nAuthentication method list for DOT1X:\n\u0026nbsp;\u0026nbsp;name=default methods=\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf the \u201cmethods\u201d under \u201cAuthentication method lists for LOGIN\u201d does not show \u201cnone\u201d, that means login authentication is enabled.\u003c/p\u003e\u003c/li\u003e\u003cli\u003eA service that accepts password-based authentication is enabled (e.g., SSH with password authentication, or telnet). By default, SSH with password authentication is enabled and telnet is disabled.\u003cbr\u003eFor SSH, use the following command to check whether it is enabled for any VRF.\u003cbr\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cpre\u003eswitch\u0026gt;show management ssh\nUser certificate authentication methods: none (neither trusted CA nor SSL profile configured)\nSSHD status for Default VRF: enabled\nSSH connection limit: 50\nSSH per host connection limit: 20\nFIPS status: disabled\neAPI subsystem: enabled\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eUse the following command to check if password-based authentication is enabled for SSH. SSH is vulnerable if \u201cpassword\u201d or \u201ckeyboard-interactive\u201d is listed.\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show run all section management ssh | grep protocol\n\u0026nbsp;\u0026nbsp;\u0026nbsp;authentication protocol keyboard-interactive public-key\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eFor Telnet, use the following command to check whether it is enabled for any VRF. Telnet is vulnerable if enabled.\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show management telnet\nTelnet status for Default VRF is enabled\u0026nbsp;\nTelnet session limit is 20\nTelnet session limit per host is 20\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eThe device is vulnerable if login authentication is enabled and SSH with password-based method or Telnet is enabled.\u003c/p\u003e\u003c/li\u003e\u003c/ol\u003e\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-19641, both of the following conditions must be met:\n\n * Login authentication must be enabled, which is the default configuration.\nThe following command can be used to verify the login authentication methods.\n\u00a0\n\n\n\nswitch\u003eshow aaa methods authentication\u00a0\nAuthentication method lists for LOGIN:\n\u00a0\u00a0name=default methods=local\nAuthentication method list for ENABLE:\n\u00a0\u00a0name=default methods=local\nAuthentication method list for DOT1X:\n\u00a0\u00a0name=default methods=\n\n\n\u00a0\n\n\n\nIf the \u201cmethods\u201d under \u201cAuthentication method lists for LOGIN\u201d does not show \u201cnone\u201d, that means login authentication is enabled.\n\n\n * A service that accepts password-based authentication is enabled (e.g., SSH with password authentication, or telnet). By default, SSH with password authentication is enabled and telnet is disabled.\nFor SSH, use the following command to check whether it is enabled for any VRF.\n\u00a0\n\n\n\nswitch\u003eshow management ssh\nUser certificate authentication methods: none (neither trusted CA nor SSL profile configured)\nSSHD status for Default VRF: enabled\nSSH connection limit: 50\nSSH per host connection limit: 20\nFIPS status: disabled\neAPI subsystem: enabled\n\n\n\u00a0\n\n\n\nUse the following command to check if password-based authentication is enabled for SSH. SSH is vulnerable if \u201cpassword\u201d or \u201ckeyboard-interactive\u201d is listed.\n\n\n\nswitch\u003eshow run all section management ssh | grep protocol\n\u00a0\u00a0\u00a0authentication protocol keyboard-interactive public-key\n\n\n\u00a0\n\n\n\nFor Telnet, use the following command to check whether it is enabled for any VRF. Telnet is vulnerable if enabled.\n\n\n\nswitch\u003eshow management telnet\nTelnet status for Default VRF is enabled\u00a0\nTelnet session limit is 20\nTelnet session limit per host is 20\n\n\n\u00a0\n\n\n\nThe device is vulnerable if login authentication is enabled and SSH with password-based method or Telnet is enabled."
}
],
"datePublic": "2026-09-09T18:15:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003eOn affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n\u003c/pre\u003e"
}
],
"value": "On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."
}
],
"impacts": [
{
"capecId": "CAPEC-130",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-130 Excessive Allocation"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-116",
"description": "CWE-116 Improper Encoding or Escaping",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T18:17:55.548Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.\n\nCVE-2026-19641 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.6M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.\n\u003c/pre\u003e"
}
],
"value": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.\n\nCVE-2026-19641 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.6M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train."
}
],
"source": {
"advisory": "Security Advisory 0152",
"defects": [
"BUG 1595868",
"BUG 1966286 (DMF)"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eThe workaround is to disable password based authentication services, such as Telnet and SSH.\u003c/p\u003e\u003cp\u003eNOTE: This workaround only works for local authentication. There is no workaround if the device requires password authentication via a remote method, e.g. Terminal Access Controller Access-Control System Plus (TACACS+), Remote Authentication Dial In User Service (RADIUS) or Lightweight Directory Access Protocol (LDAP).\u003c/p\u003e\u003cp\u003eUse the following command to disable Telnet.\u003c/p\u003e\u003cpre\u003eswitch(config)#management telnet\nswitch(config-mgmt-telnet)#shutdown\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eOn the client host, use the following command to generate SSH keys.\u003c/p\u003e\u003cpre\u003eclient# ssh-keygen -t ecdsa -b 521 -f testkey\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eCopy the SSH public key to the device and add it to the local user.\u003c/p\u003e\u003cpre\u003eswitch(config)#copy scp:\u0026lt;local_path_with_keys\u0026gt;/testkey.pub flash:\nswitch(config)#username \u0026lt;user\u0026gt; sshkey file flash:testkey.pub\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eAdd public-key as the first protocol for SSH authentication, keep keyboard-interactive as the second protocol for now.\u003c/p\u003e\u003cpre\u003eswitch(config)#management ssh\nswitch(config)#authentication protocol public-key keyboard-interactive\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eOnce you have verified that the user can know login without a password from the client host, remove keyboard-interactive from SSH authentication protocol configuration.\u003c/p\u003e\u003cpre\u003eswitch(config)#management ssh\nswitch(config)#authentication protocol public-key\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eWARNING: Incorrect configuration may block logins. Make sure public-key authentication works before removing keyboard-interactive from the configuration.\u003cbr\u003e\u003cbr\u003eInstead of public key, certificate-based authentication can also be used as a workaround for local users.\u003c/p\u003e\u003cp\u003ePlease find more details about how to configure certificate-based authentication in the \u003ca href=\"https://www.arista.com/en/support/toi/eos-4-22-1f/14286-ssh-certificates\" target=\"_blank\" rel=\"noopener noreferrer\"\u003eSSH Certificates User Guide\u003c/a\u003e.\u003c/p\u003e\u003c/pre\u003e"
}
],
"value": "The workaround is to disable password based authentication services, such as Telnet and SSH.\n\n\n\nNOTE: This workaround only works for local authentication. There is no workaround if the device requires password authentication via a remote method, e.g. Terminal Access Controller Access-Control System Plus (TACACS+), Remote Authentication Dial In User Service (RADIUS) or Lightweight Directory Access Protocol (LDAP).\n\n\n\nUse the following command to disable Telnet.\n\n\n\nswitch(config)#management telnet\nswitch(config-mgmt-telnet)#shutdown\n\n\n\u00a0\n\n\n\nOn the client host, use the following command to generate SSH keys.\n\n\n\nclient# ssh-keygen -t ecdsa -b 521 -f testkey\n\n\n\u00a0\n\n\n\nCopy the SSH public key to the device and add it to the local user.\n\n\n\nswitch(config)#copy scp:\u003clocal_path_with_keys\u003e/testkey.pub flash:\nswitch(config)#username \u003cuser\u003e sshkey file flash:testkey.pub\n\n\n\u00a0\n\n\n\nAdd public-key as the first protocol for SSH authentication, keep keyboard-interactive as the second protocol for now.\n\n\n\nswitch(config)#management ssh\nswitch(config)#authentication protocol public-key keyboard-interactive\n\n\n\u00a0\n\n\n\nOnce you have verified that the user can know login without a password from the client host, remove keyboard-interactive from SSH authentication protocol configuration.\n\n\n\nswitch(config)#management ssh\nswitch(config)#authentication protocol public-key\n\n\n\u00a0\n\n\n\nWARNING: Incorrect configuration may block logins. Make sure public-key authentication works before removing keyboard-interactive from the configuration.\n\nInstead of public key, certificate-based authentication can also be used as a workaround for local users.\n\n\n\nPlease find more details about how to configure certificate-based authentication in the SSH Certificates User Guide https://www.arista.com/en/support/toi/eos-4-22-1f/14286-ssh-certificates ."
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-19641",
"datePublished": "2026-09-15T18:17:55.548Z",
"dateReserved": "2026-08-12T16:48:22.864Z",
"dateUpdated": "2026-09-15T19:25:06.761Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73451 (GCVE-0-2026-73451)
Vulnerability from cvelistv5 – Published: 2026-09-15 18:12 – Updated: 2026-09-15 19:24
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can
Summary
On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Severity
4.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 19:24 UTC
CWE
- CWE-1419 - Incorrect Initialization of Resource
Assigner
References
1 reference
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.0.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.4M (custom) Affected: 4.34.0 , ≤ 4.34.6M (custom) Affected: 4.33.0 , ≤ 4.33.8M (custom) Affected: 4.32.0 , ≤ 4.32.11M (custom) Affected: 4.31.1F , ≤ 4.31.10M (custom) |
Date Public
2026-09-09 18:10
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73451",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:24:36.704643Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:24:42.924Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"755 Series",
"758 Series"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "4.36.0.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.4M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.6M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "4.33.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.32.11M",
"status": "affected",
"version": "4.32.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.31.10M",
"status": "affected",
"version": "4.31.1F",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eIn order to be vulnerable to CVE-2026-73451, the following condition must be met:\u003c/p\u003e\u003cp\u003eSecurity ACL must be configured on SVI in ingress direction, which by default uses a shared ACL identifier. In the example below RACLID = 1 for both switchcards:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show run interface vlan\ninterface Vlan100\n\u0026nbsp;\u0026nbsp;\u0026nbsp;ip access-group acl1 in\n \nswitch\u0026gt;show platform trident tcam acl\u0026nbsp;\n=== IP ACLs on switch SwitchcardCes1/0 ===\n \nINGRESS ACL acl1 uses 2 entries\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Assigned to VLANs: 100\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Shared ACL Identifier (RACLID): 1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Assigned to ports: None\n \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n \n=== IP ACLs on switch SwitchcardCes2/0 ===\n \nINGRESS ACL acl1 uses 2 entries\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Assigned to VLANs: 100\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Shared ACL Identifier (RACLID): 1\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Assigned to ports: None\n \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf Security ACL is \u003cb\u003enot\u003c/b\u003e configured on SVI in ingress direction, there is no exposure to this issue and the message will look something like:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show run interface vlan\ninterface Vlan100\n \nswitch\u0026gt;show platform trident tcam acl\n=== IP ACLs on switch SwitchcardCes1/0 ===\n \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n \n=== IP ACLs on switch SwitchcardCes2/0 ===\n \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73451, the following condition must be met:\n\n\n\nSecurity ACL must be configured on SVI in ingress direction, which by default uses a shared ACL identifier. In the example below RACLID = 1 for both switchcards:\n\n\n\nswitch\u003eshow run interface vlan\ninterface Vlan100\n\u00a0\u00a0\u00a0ip access-group acl1 in\n \nswitch\u003eshow platform trident tcam acl\u00a0\n=== IP ACLs on switch SwitchcardCes1/0 ===\n \nINGRESS ACL acl1 uses 2 entries\n\u00a0\u00a0\u00a0\u00a0Assigned to VLANs: 100\n\u00a0\u00a0\u00a0\u00a0Shared ACL Identifier (RACLID): 1\n\u00a0\u00a0\u00a0\u00a0Assigned to ports: None\n \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n \n=== IP ACLs on switch SwitchcardCes2/0 ===\n \nINGRESS ACL acl1 uses 2 entries\n\u00a0\u00a0\u00a0\u00a0Assigned to VLANs: 100\n\u00a0\u00a0\u00a0\u00a0Shared ACL Identifier (RACLID): 1\n\u00a0\u00a0\u00a0\u00a0Assigned to ports: None\n \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes2/0 ===\n\n\n\u00a0\n\n\n\nIf Security ACL is not configured on SVI in ingress direction, there is no exposure to this issue and the message will look something like:\n\n\n\nswitch\u003eshow run interface vlan\ninterface Vlan100\n \nswitch\u003eshow platform trident tcam acl\n=== IP ACLs on switch SwitchcardCes1/0 ===\n \n=== MAC ACLs on switch SwitchcardCes1/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes1/0 ===\n \n=== IP ACLs on switch SwitchcardCes2/0 ===\n \n=== MAC ACLs on switch SwitchcardCes2/0 ===\n \n=== IPv6 ACLs on switch SwitchcardCes2/0 ==="
}
],
"datePublic": "2026-09-09T18:10:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003eOn affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n\u003c/pre\u003e"
}
],
"value": "On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on shared SVIs to stop functioning. This may result in incorrect packet permit/deny behavior.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."
}
],
"impacts": [
{
"capecId": "CAPEC-180",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1419",
"description": "CWE-1419 Incorrect Initialization of Resource",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T18:12:44.908Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24707-security-advisory-0151"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73451 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.7M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.\n\u003c/pre\u003e"
}
],
"value": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-73451 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.7M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train."
}
],
"source": {
"advisory": "Security Advisory 0151",
"defect": [
"1262274"
],
"defects": [
"BUG 1262274"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eThe workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.\u003c/p\u003e\u003cp\u003eFor every SVI check the active ACL(s) applied to it,\u003c/p\u003e\u003cpre\u003eswitch(config)# interface Vlan\u003ci\u003eNNN\u003c/i\u003e\nswitch(config-if-Vl\u003ci\u003eNNN\u003c/i\u003e)# show active\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eThen remove the ACL(s) and re-apply them,\u003c/p\u003e\u003cpre\u003eswitch(config-if-Vl\u003ci\u003eNNN\u003c/i\u003e)# no ip access-group \u0026lt;acl name\u0026gt; in\nswitch(config-if-Vl\u003ci\u003eNNN\u003c/i\u003e)# ip access-group \u0026lt;acl name\u0026gt; in\nswitch(config-if-Vl\u003ci\u003eNNN\u003c/i\u003e)# no ipv6 access-group \u0026lt;acl name\u0026gt; in\nswitch(config-if-Vl\u003ci\u003eNNN\u003c/i\u003e)# ipv6 access-group \u0026lt;acl name\u0026gt; in\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eNote: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.\u003c/p\u003e\u003cp\u003eFor more information about Security ACLs see \u003ca href=\"https://www.arista.com/en/um-eos/eos-acls-and-route-maps\" target=\"_blank\" rel=\"noopener noreferrer\"\u003eEOS User Manual: ACLs and Route Maps\u003c/a\u003e.\u003c/p\u003e\u003c/pre\u003e"
}
],
"value": "The workaround is to re-configure (remove and reapply) the ingress IPv4 and IPv6 ACLs applied to all SVIs.\n\n\n\nFor every SVI check the active ACL(s) applied to it,\n\n\n\nswitch(config)# interface VlanNNN\nswitch(config-if-VlNNN)# show active\n\n\n\u00a0\n\n\n\nThen remove the ACL(s) and re-apply them,\n\n\n\nswitch(config-if-VlNNN)# no ip access-group \u003cacl name\u003e in\nswitch(config-if-VlNNN)# ip access-group \u003cacl name\u003e in\nswitch(config-if-VlNNN)# no ipv6 access-group \u003cacl name\u003e in\nswitch(config-if-VlNNN)# ipv6 access-group \u003cacl name\u003e in\n\n\n\u00a0\n\n\n\nNote: the security provided by the ACL configuration will not be present during the removal/reapplication of the security ACLs.\n\n\n\nFor more information about Security ACLs see EOS User Manual: ACLs and Route Maps https://www.arista.com/en/um-eos/eos-acls-and-route-maps ."
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73451",
"datePublished": "2026-09-15T18:12:44.908Z",
"dateReserved": "2026-08-12T16:42:47.921Z",
"dateUpdated": "2026-09-15T19:24:42.924Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73454 (GCVE-0-2026-73454)
Vulnerability from cvelistv5 – Published: 2026-09-16 08:14 – Updated: 2026-09-17 03:56
VLAI
EPSS
VEX
Title
Security Advisory 0165
Summary
On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 00:00 UTC
CWE
- CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.30.0F , < 4.31.0F
(custom)
Affected: 4.31.0F , < 4.32.0F (custom) Affected: 4.32.0F , < 4.33.0F (custom) Affected: 4.33.0F , ≤ 4.33.8M (custom) Affected: 4.34.0F , ≤ 4.34.7M (custom) Affected: 4.35.0F , ≤ 4.35.5M (custom) Affected: 4.36.0F , ≤ 4.36.0.1F (custom) |
Date Public
2026-09-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73454",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T03:56:53.682Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"710 Series",
"720D Series",
"720XP/722XPM Series",
"750X Series",
"7010TX Series",
"7020R/R4 Series",
"7130 Series (EOS)",
"7170 Series",
"7050X3/X4 Series",
"7060X/X2/X4/X5/X6 Series",
"7260X/X3 Series",
"7280R/R2/R3/R4 Series",
"7300X/X3 Series",
"7320X Series",
"7358X4 Series",
"7368X4 Series",
"7388X5 Series",
"7500R/R2/R3 Series",
"7800R3/R4 Series",
"7700R4 Series",
"AWE 5000 Series",
"AWE 7200R Series",
"CloudEOS",
"cEOS-lab",
"vEOS-lab",
"CloudVision eXchange"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThan": "4.31.0F",
"status": "affected",
"version": "4.30.0F",
"versionType": "custom"
},
{
"lessThan": "4.32.0F",
"status": "affected",
"version": "4.31.0F",
"versionType": "custom"
},
{
"lessThan": "4.33.0F",
"status": "affected",
"version": "4.32.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "4.33.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.36.0.1F",
"status": "affected",
"version": "4.36.0F",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn order to be vulnerable to CVE-2026-73454, the following condition must be met:\u003c/p\u003e\u003cp\u003egNSI Credentialz must be enabled (Note: gNSI Credentialz is disabled by default):\u003c/p\u003e\u003cpre\u003e\nswitch(config)#show management api gnsi\nTransport: default\nTransport enabled: yes\nServer: running on port 6030, in default VRF\n\nAcctz enabled: no\nAttestz enabled: no\nAuthz enabled: no\nCertz enabled: no\nCredentialz enabled: yes\nEnrollz enabled: no\nPathz enabled: no\n\u003c/pre\u003e\u003cp\u003eIf Credentialz is not enabled there is no exposure to this issue.\u003c/p\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73454, the following condition must be met:\n\ngNSI Credentialz must be enabled (Note: gNSI Credentialz is disabled by default):\n\n switch(config)#show management api gnsi\n Transport: default\n Transport enabled: yes\n Server: running on port 6030, in default VRF\n\n Acctz enabled: no\n Attestz enabled: no\n Authz enabled: no\n Certz enabled: no\n Credentialz enabled: yes\n Enrollz enabled: no\n Pathz enabled: no\n\nIf Credentialz is not enabled there is no exposure to this issue."
}
],
"datePublic": "2026-09-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOn affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account\u0027s properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.\u003c/p\u003e"
}
],
"value": "On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account\u0027s properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended."
}
],
"impacts": [
{
"capecId": "CAPEC-88",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-88 OS Command Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T08:14:40.485Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Arista Networks Security Advisory 0165",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24721-security-advisory-0165"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe following EOS releases contain the fix for this vulnerability:\u003c/p\u003e\u003cul\u003e\u003cli\u003e4.33.9M and later releases in the 4.33.x train\u003c/li\u003e\u003cli\u003e4.34.7.1M and later releases in the 4.34.x train\u003c/li\u003e\u003cli\u003e4.35.6M and later releases in the 4.35.x train\u003c/li\u003e\u003cli\u003e4.36.1F and later releases in the 4.36.x train\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eNo hotfix is available for this vulnerability.\u003c/p\u003e"
}
],
"value": "The following EOS releases contain the fix for this vulnerability:\n - 4.33.9M and later releases in the 4.33.x train\n - 4.34.7.1M and later releases in the 4.34.x train\n - 4.35.6M and later releases in the 4.35.x train\n - 4.36.1F and later releases in the 4.36.x train\n\nNo hotfix is available for this vulnerability."
}
],
"source": {
"advisory": "Security Advisory 0165",
"defects": [
"BUG 1602633"
],
"discovery": "INTERNAL"
},
"title": "Security Advisory 0165",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDisable gNSI Credentialz service. Note: Disabling Credentialz prevents gNSI-based credential rotation (SSH keys, passwords, host parameters) but does not affect traditional EOS CLI credential management. Credentialz is not enabled by default.\u003c/p\u003e\u003cpre\u003e\nswitch(config)#management api gnsi\nswitch(config-mgmt-api-gnsi)#no service credentialz\n\u003c/pre\u003e"
}
],
"value": "Disable gNSI Credentialz service. Note: Disabling Credentialz prevents gNSI-based credential rotation (SSH keys, passwords, host parameters) but does not affect traditional EOS CLI credential management. Credentialz is not enabled by default.\n\n switch(config)#management api gnsi\n switch(config-mgmt-api-gnsi)#no service credentialz"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73454",
"datePublished": "2026-09-16T08:14:40.485Z",
"dateReserved": "2026-08-12T16:42:47.921Z",
"dateUpdated": "2026-09-17T03:56:53.682Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73458 (GCVE-0-2026-73458)
Vulnerability from cvelistv5 – Published: 2026-09-15 19:30 – Updated: 2026-09-15 19:38
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Summary
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).
Severity
8.2 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-15 19:38 UTC
CWE
- CWE-303 - Incorrect Implementation of Authentication Algorithm
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.5M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 4.33.0 , ≤ 4.33.8M (custom) |
Date Public
2026-09-09 19:27
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73458",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-15T19:38:30.537124Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:38:38.389Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"710 Series",
"720D Series",
"720XP/722XPM Series",
"750X Series",
"7010TX Series",
"7020R/R4 Series",
"7130 Series running EOS",
"7170 Series",
"7050X3/X4 Series",
"7060X/X2/X4/X5/X6 Series",
"7260X/X3 Series",
"7280R/R2/R3/R4 Series",
"7300X/X3 Series",
"7320X Series",
"7358X4 Series",
"7368X4 Series",
"7388X5 Series",
"7500R/R2/R3 Series",
"7800R3/R4 Series",
"7700R4 Series",
"AWE 5000 Series",
"AWE 7200R Series",
"CloudEOS",
"cEOS-lab",
"vEOS-lab",
"CloudVision eXchange",
"virtual or physical appliance"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"changes": [
{
"at": "4.36.2F",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.35.6M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.34.8M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"changes": [
{
"at": "4.33.9M",
"status": "unaffected"
}
],
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "4.33.0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn order to be vulnerable to CVE-2026-73458, the following condition must be met:\u003c/p\u003e\u003cdiv\u003eBFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:\u003c/div\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cul\u003e\u003cli\u003ePassword\u003c/li\u003e\u003cli\u003eKeyed MD5\u003c/li\u003e\u003cli\u003eMeticulous MD5\u003c/li\u003e\u003cli\u003eKeyed SHA1\u003c/li\u003e\u003cli\u003eMeticulous SHA1\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eTo determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:\u0026nbsp; Version: 1 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Diagnostic: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State bit: Up\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Demand bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Poll bit: 0\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Final bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Multiplier: 20 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Length: 38\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;My Discr.: 3471785639\u0026nbsp; - Your Discr.: 2432996710\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min tx interval: 500 \u0026nbsp; - Min rx interval: 500\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min Echo interval: 500\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show running-config section bfd\nswitch\u0026gt;\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nswitch\u0026gt;\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:\u003c/p\u003e\u003cpre\u003eswitch\u0026gt;show bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:\u0026nbsp; Version: 1 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Diagnostic: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;State bit: Up\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Demand bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Poll bit: 0\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Final bit: 0\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Multiplier: 20 \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; - Length: 24\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;My Discr.: 3471785639\u0026nbsp; - Your Discr.: 2432996710\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min tx interval: 500 \u0026nbsp; - Min rx interval: 500\n\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;\u0026nbsp;Min Echo interval: 500\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73458, the following condition must be met:\n\nBFD sessions configured with authentication are affected by this issue. All supported authentication modes are impacted. The full list of authentication modes is below:\n\n\u00a0\n\n * Password\n * Keyed MD5\n * Meticulous MD5\n * Keyed SHA1\n * Meticulous SHA1\n\n\n\n\nTo determine whether your sessions are affected, run the following show command. If the authentication mode is set to anything other than None, your configuration is impacted. In the example below, the authentication mode is set to Password, indicating an affected configuration.\n\n\n\nswitch\u003eshow bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async Off, Echo Off\nLast Up 06/04/26 13:55:50.630\nLast Down 06/04/26 13:55:49.725\nLast Diag: No Diagnostic\nAuthentication mode: Password\nShared-secret profile: bfdProfile_0\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 2308, Rx Interval (ms) min/max/avg: 81/538/438 last: 188 ms ago\nTx Count: 2206, Tx Interval (ms) min/max/avg: 380/516/458 last: 476 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 1762, 2*TxInt: 443, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 16:51.08\nLast packet:\u00a0 Version: 1 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Diagnostic: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State bit: Up\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Demand bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Poll bit: 0\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Final bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Multiplier: 20 \u00a0 \u00a0 \u00a0 \u00a0 - Length: 38\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0My Discr.: 3471785639\u00a0 - Your Discr.: 2432996710\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min tx interval: 500 \u00a0 - Min rx interval: 500\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min Echo interval: 500\n\n\n\u00a0\n\n\n\nIf BFD is not configured, there is no exposure to this issue. The below show command command will return empty output:\n\n\n\nswitch\u003eshow running-config section bfd\nswitch\u003e\n\n\n\u00a0\n\n\n\nIf BFD is configured but not operational, there is no exposure to this issue. The below show command will return empty output:\n\n\n\nswitch\u003eshow bfd peers detail\nswitch\u003e\n\n\n\u00a0\n\n\n\nIf BFD is configured, and operational but not in authentication mode, there is no exposure to this issue and the output of below show command will look something like:\n\n\n\nswitch\u003eshow bfd peers detail\nVRF name: default\n-----------------\nPeer Addr 1.0.0.2, Intf Ethernet3/30/3, Type normal, Role active, State Up\nVRF default, LAddr 1.0.0.1, LD/RD 2432996710/3471785639\nSession state is Up and not using echo function\nHardware Acceleration: Async On, Echo Off\nLast Up 06/04/26 14:15:32.259\nLast Down 06/04/26 14:14:50.328\nLast Diag: No Diagnostic\nAuthentication mode: None\nShared-secret profile: None\nTxInt: 500 ms, RxInt: 500 ms, Multiplier: 20\nReceived RxInt: 500 ms, Received Multiplier: 20\nRx Count: 34, Rx Interval (ms) min/max/avg: 161/496/408 last: 163 ms ago\nTx Count: 29, Tx Interval (ms) min/max/avg: 375/499/440 last: 720 ms ago\nDetect Time: 10000 ms\nSched Delay: 1*TxInt: 76, 2*TxInt: 0, 3*TxInt: 0, GT 3*TxInt: 0\nRegistered protocols: bgp\nUptime: 13.65\nLast packet:\u00a0 Version: 1 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Diagnostic: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0State bit: Up\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Demand bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Poll bit: 0\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 - Final bit: 0\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Multiplier: 20 \u00a0 \u00a0 \u00a0 \u00a0 - Length: 24\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0My Discr.: 3471785639\u00a0 - Your Discr.: 2432996710\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min tx interval: 500 \u00a0 - Min rx interval: 500\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Min Echo interval: 500"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "This issue was discovered internally by Arista."
}
],
"datePublic": "2026-09-09T19:27:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOn affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s).\u003c/p\u003e"
}
],
"value": "On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various routing protocols monitor status on BFD session(s)."
}
],
"impacts": [
{
"capecId": "CAPEC-115",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-115 Authentication Bypass"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-303",
"description": "CWE-303 Incorrect Implementation of Authentication Algorithm",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T19:30:16.014Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24710-security-advisory-0154"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:\u003c/p\u003e\u003cul\u003e\u003cli\u003e4.36.2F and later releases in the 4.36.x train\u003c/li\u003e\u003cli\u003e4.35.6M and later releases in the 4.35.x train\u003c/li\u003e\u003cli\u003e4.34.8M and later releases in the 4.34.x train\u003c/li\u003e\u003cli\u003e4.33.9M and later releases in the 4.33.x train\u003c/li\u003e\u003c/ul\u003e"
}
],
"value": "The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73458 has been fixed in the following releases:\n\n * 4.36.2F and later releases in the 4.36.x train\n * 4.35.6M and later releases in the 4.35.x train\n * 4.34.8M and later releases in the 4.34.x train\n * 4.33.9M and later releases in the 4.33.x train"
}
],
"source": {
"advisory": "154",
"defect": [
"1787150"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eNo mitigation is available for this issue.\u003c/p\u003e"
}
],
"value": "No mitigation is available for this issue."
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73458",
"datePublished": "2026-09-15T19:30:16.014Z",
"dateReserved": "2026-08-12T16:45:03.510Z",
"dateUpdated": "2026-09-15T19:38:38.389Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73464 (GCVE-0-2026-73464)
Vulnerability from cvelistv5 – Published: 2026-09-16 08:32 – Updated: 2026-09-17 03:56
VLAI
EPSS
VEX
Title
Security Advisory 0166
Summary
On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 00:00 UTC
CWE
- CWE-94 - Improper Control of Generation of Code ('Code Injection')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.29.0F , < 4.30.0F
(custom)
Affected: 4.30.0F , < 4.31.0F (custom) Affected: 4.31.0F , < 4.32.0F (custom) Affected: 4.32.0F , < 4.33.0F (custom) Affected: 4.33.0F , ≤ 4.33.8M (custom) Affected: 4.34.0F , ≤ 4.34.7M (custom) Affected: 4.35.0F , ≤ 4.35.5M (custom) Affected: 4.36.0F , ≤ 4.36.0.1F (custom) |
Date Public
2026-09-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73464",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T03:56:52.621Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"710 Series",
"720D Series",
"720XP/722XPM Series",
"750X Series",
"7010TX Series",
"7020R/R4 Series",
"7130 Series (EOS)",
"7170 Series",
"7050X3/X4 Series",
"7060X/X2/X4/X5/X6 Series",
"7260X/X3 Series",
"7280R/R2/R3/R4 Series",
"7300X/X3 Series",
"7320X Series",
"7358X4 Series",
"7368X4 Series",
"7388X5 Series",
"7500R/R2/R3 Series",
"7800R3/R4 Series",
"7700R4 Series",
"AWE 5000 Series",
"AWE 7200R Series",
"CloudEOS",
"cEOS-lab",
"vEOS-lab",
"CloudVision eXchange, virtual or physical appliance"
],
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThan": "4.30.0F",
"status": "affected",
"version": "4.29.0F",
"versionType": "custom"
},
{
"lessThan": "4.31.0F",
"status": "affected",
"version": "4.30.0F",
"versionType": "custom"
},
{
"lessThan": "4.32.0F",
"status": "affected",
"version": "4.31.0F",
"versionType": "custom"
},
{
"lessThan": "4.33.0F",
"status": "affected",
"version": "4.32.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.8M",
"status": "affected",
"version": "4.33.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.5M",
"status": "affected",
"version": "4.35.0F",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.36.0.1F",
"status": "affected",
"version": "4.36.0F",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn order to be vulnerable to CVE-2026-73464, the following condition must be met:\u003c/p\u003e\u003cp\u003egNMI transport must be enabled:\u003c/p\u003e\u003cpre\u003e\nswitch(config)#show management api gnmi\nTransport: default\nEnabled: yes\nServer: running on port 6030, in default VRF\nSSL profile: none\nQoS DSCP: none\nConnection limit: 100\nAuthorization required: no\nAccounting requests: no\nNotification timestamp: last change time\nListen addresses: ::\nAuthentication username priority: x509-spiffe, metadata, x509-common-name\nConfig-commands AAA accounting: enabled\nConfig-commands AAA authorization: enabled\n\u003c/pre\u003e\u003cp\u003eIf a gNMI transport is not configured there is no exposure to this issue and the message will look something like:\u003c/p\u003e\u003cpre\u003e\nswitch(config)#show management api gnmi\nEnabled: no transports enabled\n\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73464, the following condition must be met:\n\ngNMI transport must be enabled:\n\n switch(config)#show management api gnmi\n Transport: default\n Enabled: yes\n Server: running on port 6030, in default VRF\n SSL profile: none\n QoS DSCP: none\n Connection limit: 100\n Authorization required: no\n Accounting requests: no\n Notification timestamp: last change time\n Listen addresses: ::\n Authentication username priority: x509-spiffe, metadata, x509-common-name\n Config-commands AAA accounting: enabled\n Config-commands AAA authorization: enabled\n\nIf a gNMI transport is not configured there is no exposure to this issue and the message will look something like:\n\n switch(config)#show management api gnmi\n Enabled: no transports enabled"
}
],
"datePublic": "2026-09-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eOn affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch.\u003c/p\u003e"
}
],
"value": "On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbitrary code with root privileges on the switch."
}
],
"impacts": [
{
"capecId": "CAPEC-242",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-242 Code Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T08:32:54.304Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Arista Networks Security Advisory 0166",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24722-security-advisory-0166"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eThe following EOS releases contain the fix for this vulnerability:\u003c/p\u003e\u003cul\u003e\u003cli\u003e4.33.9M and later releases in the 4.33.x train\u003c/li\u003e\u003cli\u003e4.34.7.1M and later releases in the 4.34.x train\u003c/li\u003e\u003cli\u003e4.35.6M and later releases in the 4.35.x train\u003c/li\u003e\u003cli\u003e4.36.1F and later releases in the 4.36.x train\u003c/li\u003e\u003c/ul\u003e\u003cp\u003eNo hotfix is available for this vulnerability.\u003c/p\u003e"
}
],
"value": "The following EOS releases contain the fix for this vulnerability:\n - 4.33.9M and later releases in the 4.33.x train\n - 4.34.7.1M and later releases in the 4.34.x train\n - 4.35.6M and later releases in the 4.35.x train\n - 4.36.1F and later releases in the 4.36.x train\n\nNo hotfix is available for this vulnerability."
}
],
"source": {
"advisory": "Security Advisory 0166",
"defects": [
"BUG 1602598",
"BUG 1966288"
],
"discovery": "INTERNAL"
},
"title": "Security Advisory 0166",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eDisable any gNMI transports:\u003c/p\u003e\u003cpre\u003e\nmanagement api gnmi\n no transport grpc \u0026lt;name\u0026gt;\n\u003c/pre\u003e\u003cp\u003eDisabling all gNMI transports makes gNMI, gNOI, and gNSI services unavailable. If no RESTCONF or NETCONF transports are configured, the OpenConfig/Octa agent will also stop. CloudVision provisioning via TerminAttr is unaffected. All services resume when a gNMI transport is re-enabled.\u003c/p\u003e\u003cp\u003eNote: This mitigation is not applicable to DMF-managed EOS switches. gNMI transports are enabled by default on these platforms and cannot be disabled.\u003c/p\u003e"
}
],
"value": "Disable any gNMI transports:\n\n management api gnmi\n no transport grpc \u003cname\u003e\n\nDisabling all gNMI transports makes gNMI, gNOI, and gNSI services unavailable. If no RESTCONF or NETCONF transports are configured, the OpenConfig/Octa agent will also stop. CloudVision provisioning via TerminAttr is unaffected. All services resume when a gNMI transport is re-enabled.\n\nNote: This mitigation is not applicable to DMF-managed EOS switches. gNMI transports are enabled by default on these platforms and cannot be disabled."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73464",
"datePublished": "2026-09-16T08:32:54.304Z",
"dateReserved": "2026-08-12T16:45:03.511Z",
"dateUpdated": "2026-09-17T03:56:52.621Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73465 (GCVE-0-2026-73465)
Vulnerability from cvelistv5 – Published: 2026-09-15 18:36 – Updated: 2026-09-17 11:57
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS, under certain circumstances plaintext private keys
Summary
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.
To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 03:57 UTC
CWE
- CWE-532 - Insertion of Sensitive Information into Log File
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.4M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 0.0.0 , ≤ 4.33.9M (custom) Affected: 0 , ≤ 4.32.0 (custom) Affected: 0 , ≤ 4.31.0 (custom) |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73465",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T03:57:04.010625Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T11:57:21.646Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.4M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.9M",
"status": "affected",
"version": "0.0.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.32.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.31.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eIn order to be vulnerable to CVE-2026-73465, the following condition must be met:\u003c/p\u003e\u003cp\u003eMgmtSecuritySslCertKey trace levels 0, 3 and/or 4, on agent ConfigAgent, must be enabled.\u003c/p\u003e\u003cpre\u003eswitch# show trace ConfigAgent | grep MgmtSecuritySslCertKey MgmtSecuritySslCertKey enabled\u0026nbsp; 01.34......\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eIf MgmtSecuritySslCertKey traces levels 0, 3 and 4 are disabled, there is no exposure to this issue and the message will look something like:\u003c/p\u003e\u003cpre\u003eswitch# show trace ConfigAgent | grep MgmtSecuritySslCertKey MgmtSecuritySslCertKey enabled\u0026nbsp; ...........\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73465, the following condition must be met:\n\n\n\nMgmtSecuritySslCertKey trace levels 0, 3 and/or 4, on agent ConfigAgent, must be enabled.\n\n\n\nswitch# show trace ConfigAgent | grep MgmtSecuritySslCertKey MgmtSecuritySslCertKey enabled\u00a0 01.34......\n\n\n\u00a0\n\n\n\nIf MgmtSecuritySslCertKey traces levels 0, 3 and 4 are disabled, there is no exposure to this issue and the message will look something like:\n\n\n\nswitch# show trace ConfigAgent | grep MgmtSecuritySslCertKey MgmtSecuritySslCertKey enabled\u00a0 ..........."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003eOn affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\u003cbr\u003e\u003cbr\u003eTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n\u003c/pre\u003e"
}
],
"value": "On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."
}
],
"impacts": [
{
"capecId": "CAPEC-37",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-37 Retrieve Embedded Sensitive Data"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532 Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T18:36:51.963Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Arista Security Advisory 0153",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\nCVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.\n\u003c/pre\u003e"
}
],
"value": "CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train."
}
],
"source": {
"advisory": "Security Advisory 0153",
"defects": [
"BUG 1595862",
"BUG 1966285 (DMF)"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS, under certain circumstances plaintext private keys",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eThis vulnerability may lead to exposed private keys on log files. As such, the following messages may appear at /var/log/agents/ConfigAgent-*:\u003c/p\u003e\u003cpre\u003e2026-05-07 02:42:18.537932 18813 MgmtSecuritySslCertK 3 validateRsaPrivateKey start: -----BEGIN RSA PRIVATE KEY-----\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cpre\u003e2026-05-07 02:42:18.537932 18813 MgmtSecuritySslCertK 3 _getPemCount start: -----BEGIN EC PRIVATE KEY-----\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eThese messages can be found with the following grep command, when run from the bash shell:\u003c/p\u003e\u003cpre\u003eswitch# grep \"MgmtSecuritySslCertK\" /var/log/agents/ConfigAgent-* | grep \"PRIVATE KEY---\"\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "This vulnerability may lead to exposed private keys on log files. As such, the following messages may appear at /var/log/agents/ConfigAgent-*:\n\n\n\n2026-05-07 02:42:18.537932 18813 MgmtSecuritySslCertK 3 validateRsaPrivateKey start: -----BEGIN RSA PRIVATE KEY-----\n\n\n\u00a0\n\n\n\n2026-05-07 02:42:18.537932 18813 MgmtSecuritySslCertK 3 _getPemCount start: -----BEGIN EC PRIVATE KEY-----\n\n\n\u00a0\n\n\n\nThese messages can be found with the following grep command, when run from the bash shell:\n\n\n\nswitch# grep \"MgmtSecuritySslCertK\" /var/log/agents/ConfigAgent-* | grep \"PRIVATE KEY---\""
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73465",
"datePublished": "2026-09-15T18:36:51.963Z",
"dateReserved": "2026-08-12T16:47:18.121Z",
"dateUpdated": "2026-09-17T11:57:21.646Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73466 (GCVE-0-2026-73466)
Vulnerability from cvelistv5 – Published: 2026-09-15 18:41 – Updated: 2026-09-17 11:57
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS, under certain circumstances plaintext user passwords
Summary
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.
To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 03:57 UTC
CWE
- CWE-532 - Insertion of Sensitive Information into Log File
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.4M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 0.0.0 , ≤ 4.33.9M (custom) Affected: 0 , ≤ 4.32.0 (custom) Affected: 0 , ≤ 4.31.0 (custom) |
Date Public
2026-09-09 18:37
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73466",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T03:57:02.522424Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T11:57:34.875Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.4M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.9M",
"status": "affected",
"version": "0.0.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.32.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.31.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eIn order to be vulnerable to CVE-2026-73466, the following condition must be met:\u003c/p\u003e\u003cp\u003ePyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cPyServer\u201d. The level from the output can be 4 or any range that includes 4, e.g. \u201c0-7\u201d or \u201c*\u201d.\u003c/p\u003e\u003cp\u003eThis is an example showing the trace setting \u201cPy*\u201d with level with \u201c0-5\u201d, which will leak the password:\u003c/p\u003e\u003cpre\u003eswitch# show run section trace | grep Aaa\ntrace Aaa setting Py*/0-5\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73466, the following condition must be met:\n\n\n\nPyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cPyServer\u201d. The level from the output can be 4 or any range that includes 4, e.g. \u201c0-7\u201d or \u201c*\u201d.\n\n\n\nThis is an example showing the trace setting \u201cPy*\u201d with level with \u201c0-5\u201d, which will leak the password:\n\n\n\nswitch# show run section trace | grep Aaa\ntrace Aaa setting Py*/0-5"
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Impact on DANZ Monitoring Fabric (DMF)\u003cp\u003eDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\u003c/p\u003e\u003cp\u003eDMF fabric switches running Switch Light OS are not affected by this vulnerability.\u003c/p\u003e\u003cp\u003eCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\u003c/p\u003e\u003cpre\u003eDMF-CONTROLLER\u0026gt; show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; True\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; True\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; False \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; x86_64-ccs-720df-48y-eos\u003c/pre\u003e"
}
],
"value": "Impact on DANZ Monitoring Fabric (DMF)\n\nDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\n\n\n\nDMF fabric switches running Switch Light OS are not affected by this vulnerability.\n\n\n\nCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\n\n\n\nDMF-CONTROLLER\u003e show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 True\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 True\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 False \u00a0 \u00a0 \u00a0 \u00a0 x86_64-ccs-720df-48y-eos"
}
],
"datePublic": "2026-09-09T18:37:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003eOn affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\u003cbr\u003e\u003cbr\u003eTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n\u003c/pre\u003e"
}
],
"value": "On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."
}
],
"impacts": [
{
"capecId": "CAPEC-37",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-37 Retrieve Embedded Sensitive Data"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532 Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T18:41:04.230Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Arista Security Advisory 0153",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\nCVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.\n\u003c/pre\u003e"
}
],
"value": "CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train."
}
],
"source": {
"advisory": "Security Advisory 0153",
"defects": [
"BUG 1595866",
"BUG 1966285 (DMF)"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS, under certain circumstances plaintext user passwords",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eThe workaround is to disable PyServer level 4 tracing on agent Aaa.\u003c/p\u003e\u003cpre\u003eswitch(config)# no trace Aaa enable PyServer levels 4\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "The workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n\n\nswitch(config)# no trace Aaa enable PyServer levels 4"
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73466",
"datePublished": "2026-09-15T18:41:04.230Z",
"dateReserved": "2026-08-12T16:47:18.121Z",
"dateUpdated": "2026-09-17T11:57:34.875Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73467 (GCVE-0-2026-73467)
Vulnerability from cvelistv5 – Published: 2026-09-15 18:44 – Updated: 2026-09-16 15:51
VLAI
EPSS
VEX
Title
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
Summary
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 03:57 UTC
CWE
- CWE-532 - Insertion of Sensitive Information into Log File
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://www.arista.com/en/support/advisories-noti… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Arista Networks | EOS |
Affected:
4.36.0 , ≤ 4.36.1F
(custom)
Affected: 4.35.0 , ≤ 4.35.4M (custom) Affected: 4.34.0 , ≤ 4.34.7M (custom) Affected: 0.0.0 , ≤ 4.33.9M (custom) Affected: 0 , ≤ 4.32.0 (custom) Affected: 0 , ≤ 4.31.0 (custom) |
Date Public
2026-09-09 18:37
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73467",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T03:57:06.873994Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T15:51:26.451Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "EOS",
"vendor": "Arista Networks",
"versions": [
{
"lessThanOrEqual": "4.36.1F",
"status": "affected",
"version": "4.36.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.35.4M",
"status": "affected",
"version": "4.35.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.34.7M",
"status": "affected",
"version": "4.34.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.33.9M",
"status": "affected",
"version": "0.0.0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.32.0",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"lessThanOrEqual": "4.31.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eIn order to be vulnerable to CVE-2026-73467, the following condition must be met:\u003c/p\u003e\u003cp\u003eTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cTacacs\u201d. The level from the output can be 6 or any range that includes 6, e.g. \u201c0-7\u201d or \u201c*\u201d.\u003c/p\u003e\u003cp\u003eThis is an example showing the trace setting \u201cTacacs*\u201d with level with \u201c0-7\u201d, which will leak the password:\u003c/p\u003e\u003cpre\u003eswitch# show run section trace | grep Aaa\ntrace Aaa setting Tacacs*/0-7\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "In order to be vulnerable to CVE-2026-73467, the following condition must be met:\n\n\n\nTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cTacacs\u201d. The level from the output can be 6 or any range that includes 6, e.g. \u201c0-7\u201d or \u201c*\u201d.\n\n\n\nThis is an example showing the trace setting \u201cTacacs*\u201d with level with \u201c0-7\u201d, which will leak the password:\n\n\n\nswitch# show run section trace | grep Aaa\ntrace Aaa setting Tacacs*/0-7"
},
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Impact on DANZ Monitoring Fabric (DMF)\u003cp\u003eDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\u003c/p\u003e\u003cp\u003eDMF fabric switches running Switch Light OS are not affected by this vulnerability.\u003c/p\u003e\u003cp\u003eCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\u003c/p\u003e\u003cpre\u003eDMF-CONTROLLER\u0026gt; show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; True\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; True\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; False \u0026nbsp; \u0026nbsp; \u0026nbsp; \u0026nbsp; x86_64-ccs-720df-48y-eos\u003c/pre\u003e"
}
],
"value": "Impact on DANZ Monitoring Fabric (DMF)\n\nDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\n\n\n\nDMF fabric switches running Switch Light OS are not affected by this vulnerability.\n\n\n\nCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\n\n\n\nDMF-CONTROLLER\u003e show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 True\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 True\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi\u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 \u00a0 False \u00a0 \u00a0 \u00a0 \u00a0 x86_64-ccs-720df-48y-eos"
}
],
"datePublic": "2026-09-09T18:37:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003eOn affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers\n\u003c/pre\u003e"
}
],
"value": "On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers"
}
],
"impacts": [
{
"capecId": "CAPEC-37",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-37 Retrieve Embedded Sensitive Data"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "LOCAL",
"baseScore": 6,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "HIGH",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-532",
"description": "CWE-532 Insertion of Sensitive Information into Log File",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T18:44:39.048Z",
"orgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"shortName": "Arista"
},
"references": [
{
"name": "Arista Security Advisory 0153",
"tags": [
"vendor-advisory"
],
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\nCVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.\n\u003c/pre\u003e"
}
],
"value": "CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train."
}
],
"source": {
"advisory": "Security Advisory 0153",
"defects": [
"BUG 1595862",
"BUG 1966285 (DMF)"
],
"discovery": "INTERNAL"
},
"title": "On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cpre\u003e\u003cp\u003eThe workaround is to disable Tacacs level 6 tracing on agent Aaa.\u003c/p\u003e\u003cpre\u003eswitch(config)# no trace Aaa enable Tacacs levels 6\u003cbr\u003e\u003cbr\u003eClean Up Existing Log Files\u003cp\u003eIf any of the above agent logging levels have been enabled, it\u2019s necessary to clean up the existing log files to remove the already leaked secrets and keys.\u003c/p\u003e\u003cp\u003eUse the following commands to clean up Aaa or ConfigAgent log files:\u003c/p\u003e\u003cpre\u003eswitch(config)# bash sudo truncate -s 0 /var/log/agents/Aaa*\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/ConfigAgent*\n\u003c/pre\u003e\u003cdiv\u003e\u0026nbsp;\u003c/div\u003e\u003cp\u003eThen use the following commands to clean up previously rotated old log files:\u003c/p\u003e\u003cpre\u003eswitch(config)# bash sudo find /var/log/agents -name \u0027Aaa*.gz\u0027 -type f -delete\nswitch(config)# bash sudo find /var/log/agents -name \u0027ConfigAgent*.gz\u0027 -type f -delete\u003c/pre\u003e\u003c/pre\u003e\u003c/pre\u003e"
}
],
"value": "The workaround is to disable Tacacs level 6 tracing on agent Aaa.\n\n\n\nswitch(config)# no trace Aaa enable Tacacs levels 6\n\nClean Up Existing Log Files\n\nIf any of the above agent logging levels have been enabled, it\u2019s necessary to clean up the existing log files to remove the already leaked secrets and keys.\n\n\n\nUse the following commands to clean up Aaa or ConfigAgent log files:\n\n\n\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/Aaa*\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/ConfigAgent*\n\n\n\u00a0\n\n\n\nThen use the following commands to clean up previously rotated old log files:\n\n\n\nswitch(config)# bash sudo find /var/log/agents -name \u0027Aaa*.gz\u0027 -type f -delete\nswitch(config)# bash sudo find /var/log/agents -name \u0027ConfigAgent*.gz\u0027 -type f -delete"
}
],
"x_generator": {
"engine": "Vulnogram 1.0.5"
}
}
},
"cveMetadata": {
"assignerOrgId": "c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7",
"assignerShortName": "Arista",
"cveId": "CVE-2026-73467",
"datePublished": "2026-09-15T18:44:39.048Z",
"dateReserved": "2026-08-12T16:47:18.121Z",
"dateUpdated": "2026-09-16T15:51:26.451Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…