Executive brief
Arista EOS network switches can expose SNMPv3 authentication credentials in their configuration files when SNMP is enabled. An authenticated attacker who accesses the device's running configuration could use the exposed credential hashes to perform unauthorized read operations on network management data or send fraudulent alerts to monitoring systems, potentially disrupting network operations or gaining visibility into sensitive network information.
Technical details
This vulnerability is a sensitive information disclosure (CWE-212) affecting Arista EOS when SNMPv3 is configured with local or remote users. The root cause is improper handling of SNMPv3 authentication key material, which appears as one-way hashed values in the device's running and sanitized configurations. An authenticated user with access to the device configuration can extract these hashes and potentially crack or replay them to impersonate legitimate SNMP users. The attack requires SNMPv3 to be configured and an authenticated session to the device; exploitation allows unauthorized read access to SNMP tables and injection of fraudulent trap notifications to the Network Management System. Patches are available in patched EOS versions (4.36.2F and later, 4.35.6M and later, 4.34.8.1M and later, 4.33.10M and later).
Affected products
- Arista EOS 4.36.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7.1M and below (4.34.x), 4.33.9M and below (4.33.x), and all prior releases
Timeline
- 2026-09-16: disclosed
- 2026-09-09: advisory: Arista Security Advisory 0178 published