Junglewise Threat Intelligence

CVE-2026-2380: Arista EOS sensitive data logging in OpenConfig services

CVE-2026-2380 · Severity: high · CVSS 7.4 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS devices with OpenConfig management services (gNMI, gNSI, RESTCONF, NETCONF) may unintentionally log sensitive information such as passwords and authentication credentials. These logs can be stored locally on the device or forwarded to remote accounting servers, potentially exposing critical secrets to unauthorized access or system administrators. The vulnerability requires these management services to be enabled and is not present in other Arista products like CloudVision or firewalls.

Technical details

This vulnerability (CWE-256: Plaintext Storage of a Password) occurs when OpenConfig/Octa agents log sensitive CLI commands and YANG configuration leafs in plaintext during gNMI, NETCONF, RESTCONF, or gNSI interactions. The root cause is unintentional logging of sensitive requests and responses by default when any of these management servers are enabled, with additional exposure if debug tracing is active or remote AAA accounting is configured. Attack vector is network-based and requires authentication (PR:L); an authenticated attacker can review local logs or remote syslog/accounting servers to extract credentials. No known public exploitation has been reported. Patches are available in EOS 4.36.1F+ (4.36 train) and later versions.

Affected products

  • Arista EOS 4.36.1F and below (4.36.x), all 4.35.x, all 4.34.x, all 4.33.x, and prior releases

Timeline

  • 2026-09-09: disclosed: Security Advisory 0168 initial release
  • 2026-09-16: advisory: CVE-2026-2380 published on NVD

References

Related threats