🔐 CVE Alert

CVE-2026-73466

MEDIUM 6.3

On affected platforms running Arista EOS, under certain circumstances plaintext user passwords

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CWE CWE-532
Vendor arista networks
Product eos
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for arista networks eos

Be the first to know when new medium vulnerabilities affecting arista networks eos are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Arista Networks / EOS
4.36.0 ≤ 4.36.1F 4.35.0 ≤ 4.35.4M 4.34.0 ≤ 4.34.7M 0.0.0 ≤ 4.33.9M 0 ≤ 4.32.0 0 ≤ 4.31.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
arista.com: https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153