Junglewise Threat Intelligence

CVE-2026-19641: Arista EOS orphan authentication session denial of service

CVE-2026-19641 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Executive brief

Arista EOS, networking software that manages switching and routing operations in data center and cloud infrastructure, contains a flaw in password handling that allows attackers to create orphan authentication sessions. Repeated exploitation exhausts available authentication resources and blocks legitimate administrators and users from logging into affected devices, disrupting network operations and management capabilities.

Technical details

The vulnerability is an improper encoding or escaping flaw (CWE-116) in the password authentication mechanism. A specially crafted password can cause authentication sessions to become orphaned (not properly closed), and repeated submission exhausts finite authentication session resources. The attack requires no prior authentication and is reachable over the network via SSH (with password authentication enabled) or Telnet. The result is a denial of service affecting device accessibility. Patches are available in fixed EOS versions: 4.36.1F and later, 4.35.6M and later, 4.34.8M and later, and 4.33.9M and later.

Affected products

  • Arista EOS 4.36.0F and below 4.36.x, 4.35.5M and below 4.35.x, 4.34.7.1M and below 4.34.x, 4.33.8M and below 4.33.x, and all prior releases

Timeline

  • 2026-09-09: disclosed: Security Advisory 0152 initial release
  • 2026-09-15: other: Published to NVD

References

Related threats