CVE-2026-73466
Received Received - Intake

Arista EOS Cleartext Password Logging Vulnerability

Vulnerability report for CVE-2026-73466, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-16

Assigner: Arista Networks, Inc.

Description

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
arista eos *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Arista EOS devices writing user passwords in clear text to log files when specific non-standard debugging trace levels are enabled. Exploitation requires authenticated local administrative access and the explicit activation of these debugging levels.

Detection Guidance

Detection requires checking for clear text passwords in log files when specialized non-standard debugging trace levels are enabled. Review system logs for entries containing passwords during debugging sessions. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could allow an attacker with local administrative access to retrieve plaintext passwords from log files, potentially leading to unauthorized access to the device or network. However, exploitation requires prior access and specific debugging conditions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements for data protection such as GDPR or HIPAA, which mandate strict controls over access to personal or health information.

Mitigation Strategies

Disable any non-standard debugging trace levels that are not required for normal operations. Ensure all user passwords are changed if they may have been exposed. Restrict local administrative access to authorized personnel only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73466. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart