Arista NetworksCVE-2026-19641
Arista Networks EOS: improper output encoding
Medium6.9CVE-2026-19641 · Published Sep 15, 2026 · updated Sep 16, 2026
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.36.0, <= 4.36.0F | No fix yet |
| >= 4.35.0, <= 4.35.5M | No fix yet | |
| >= 4.34.0, <= 4.34.7.1M | No fix yet | |
| >= 0.0.0, <= 4.33.8M | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-116
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Arista Networks EOS: denial of service | Medium6.5 | No fix yet |
| Sep 15 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header | Medium5.3 | No fix yet |
| Sep 15 | Arista Networks EOS: improper input validation | High7.1 | No fix yet |
| Sep 15 | On affected platforms running Arista EOS with authenticated Bidirectional... | Critical9.2 | No fix yet |
| Sep 15 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 15 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |