CVE-2026-73465
Received Received - Intake

Arista EOS Plaintext Private Key Exposure in Logs

Vulnerability report for CVE-2026-73465, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-16

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves plaintext private keys being written to log files on Arista EOS devices when specialized non-standard debugging trace levels are enabled. Exploitation requires authenticated local administrative access and explicit enabling of these debugging levels.

Detection Guidance

Detection requires checking log files for plaintext private keys when non-standard debugging trace levels are enabled. Review logs for sensitive data exposure and verify if specialized debugging was active during operations.

Impact Analysis

If exploited, attackers with local access could retrieve private keys from logs, potentially leading to unauthorized access, data breaches, or further network compromise. However, exploitation requires high privileges and specific conditions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations must ensure proper access controls and avoid enabling debug levels to maintain compliance.

Mitigation Strategies

Disable non-standard debugging trace levels on affected Arista EOS devices. Ensure no plaintext private keys remain in logs. Restrict local administrative access to authorized personnel only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73465. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart