Junglewise Threat Intelligence

CVE-2026-73465: Arista EOS sensitive information insertion in log files

CVE-2026-73465 · Severity: medium · CVSS 6.3 · Published 2026-09-15

Executive brief

Arista EOS network switches can accidentally write sensitive credentials—private keys, user passwords, and TACACS+ secrets—to log files when specialized debugging features are explicitly enabled. An attacker with local administrative shell access can read these exposed credentials from the logs, potentially compromising authentication systems and gaining unauthorized access to network infrastructure.

Technical details

This vulnerability is a sensitive information logging flaw (CWE-532) affecting Arista EOS across multiple series and software versions. The root cause is improper output filtering in the ConfigAgent trace subsystem; when non-standard debugging trace levels (0, 3, and/or 4) are explicitly enabled on MgmtSecuritySslCertKey, plaintext credentials are written to log files. Exploitation requires authenticated local administrative access to the device shell and the presence of enabled debug traces—a high privilege and high configuration barrier. An attacker can recover private keys, passwords, and TACACS+ shared secrets from logs, potentially escalating access or compromising authentication infrastructure. Patches are available in fixed versions: EOS 4.36.2F and later, 4.35.5M and later, 4.34.8M and later, and 4.33.10M and later.

Affected products

  • Arista EOS 4.36.1F and earlier 4.36.x, 4.35.4M and earlier 4.35.x, 4.34.7M and earlier 4.34.x, 4.33.9M and earlier 4.33.x, all 4.32.x and 4.31.x releases

Timeline

  • 2026-09-09: disclosed: Arista Security Advisory 0153 initial release
  • 2026-09-15: advisory: CVE-2026-73465 published on NVD

References

Related threats