Arista Networks EOS: secrets in logs
Medium6.0CVE-2026-73466 · Published Sep 15, 2026 · updated Sep 17, 2026
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EOS Product | >= 4.36.0, <= 4.36.1F | No fix yet |
| >= 4.35.0, <= 4.35.4M | No fix yet | |
| >= 4.34.0, <= 4.34.7M | No fix yet | |
| >= 0.0.0, <= 4.33.9M | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-532
More Arista Networks advisories
All Arista Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Arista Networks EOS: denial of service | Medium6.5 | No fix yet |
| Sep 15 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header | Medium5.3 | No fix yet |
| Sep 15 | Arista Networks EOS: improper input validation | High7.1 | No fix yet |
| Sep 15 | On affected platforms running Arista EOS with authenticated Bidirectional... | Critical9.2 | No fix yet |
| Sep 15 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |
| Sep 15 | Arista Networks EOS: secrets in logs | Medium6.0 | No fix yet |