Executive brief
Arista EOS network switches may write sensitive authentication credentials—including TACACS+ shared secrets, user passwords, and private keys—to log files when specialized debugging features are enabled. An attacker with authenticated administrative access to the device shell could retrieve these credentials from logs, potentially compromising network authentication infrastructure and enabling lateral movement or account hijacking.
Technical details
This vulnerability is an information disclosure flaw (CWE-532) affecting Arista EOS where plaintext TACACS+ shared secrets, user passwords, and private keys are inadvertently written to log files during operations. The root cause is insufficient filtering of sensitive data when specialized non-standard debugging trace levels (ConfigAgent MgmtSecuritySslCertKey levels 0, 3, 4 for CVE-2026-73465; equivalent debug traces for CVE-2026-73466 and CVE-2026-73467) are explicitly enabled. Exploitation requires an authenticated attacker with local administrative shell access and the ability to enable or trigger these debug traces. An attacker can then read log files to extract credentials and use them for authentication bypass or further network compromise. The vulnerability affects EOS versions up to 4.36.1F on multiple Arista platforms (7050, 7060, 7250, 7280, 7300, 7500, 7800 series and others); patches are available in later releases (e.g., EOS-4.36.2F). Arista reports no known wild exploitation.
Affected products
- Arista EOS 4.36.1F and earlier in 4.36.x; 4.35.4M and earlier in 4.35.x; 4.34.7M and earlier in 4.34.x; 4.33.9M and earlier in 4.33.x; all 4.32.x and 4.31.x releases
Timeline
- 2026-09-09: advisory: Arista Security Advisory 0153 initial release (revision 1.0)
- 2026-09-15: disclosed: CVE-2026-73467 published on NVD
- 2026-09-22: other: Arista Security Advisory 0153 revision 1.1 with CSAF JSON file