Executive brief
Arista EOS switches with the gRPC Network Packet Sampling Interface (gNPSI) enabled may log client credentials in clear text to local and remote accounting logs, exposing authentication details to anyone with access to those logs. This vulnerability requires specific authentication configuration and explicit trace facility enabling, limiting exposure to environments with particular gNPSI settings enabled.
Technical details
This is an improper logging vulnerability (CWE-532) in Arista EOS gNPSI where client credentials are written in clear text to accounting logs under certain configuration circumstances. The vulnerability occurs when gNPSI is explicitly configured with the EosRpcAuth trace facility enabled, allowing authenticated users with access to local or remote accounting logs to view sensitive credentials. Attack vector is network-based and requires prior authentication to the device; exploitation has no user interaction requirement. Affected EOS versions include 4.36.1F and below, 4.35.5M and below, and specific 4.34.x releases. Mitigation involves configuring mutual TLS with only x509-spiffe authentication enabled.
Affected products
- Arista EOS 4.36.1F and below (4.36.x train), 4.35.5M and below (4.35.x train), 4.34.2F through 4.34.7M (4.34.x train)
- Arista CloudEOS affected versions aligned with EOS releases
- Arista cEOS-lab affected versions aligned with EOS releases
- Arista vEOS-lab affected versions aligned with EOS releases
Timeline
- 2026-09-09: advisory: Arista Security Advisory 0158 initial release
- 2026-09-22: other: CSAF JSON file added to advisory
- 2026-09-16: disclosed: CVE published in NVD