Description
On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via authentication resource exhaustion
Action: Patch Upgrade
AI Analysis

Impact

The vulnerability allows an attacker to send a specially crafted password when password authentication is enabled on Arista EOS. The malformed credential creates orphan authentication sessions, gradually draining the system’s authentication session pool. When the pool is exhausted legitimate users will be unable to log in, causing a denial‑of‑service condition that affects the device’s availability. The weakness is an improper handling of authentication data, mapped to CWE‑116.

Affected Systems

Affected platforms are Arista Networks EOS where password‑based authentication is configured, including Telnet and SSH services. The fix is included in EOS releases 4.36.1F and later in the 4.36.x train, 4.35.6M and later in the 4.35.x train, 4.34.8M and later in the 4.34.x train, and 4.33.9M and later in the 4.33.x train.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is 0.00343 (< 1 %), and the vulnerability is not listed in CISA KEV, so there is no current evidence of widespread exploitation. The likely attack vector is via remote password authentication attempts over Telnet or SSH, which an attacker could perform from an external host if that service is enabled. Because the flaw leaks authentication sessions, even automated login scripts can trigger it, making the risk higher for systems exposed to the internet.

Generated by OpenCVE AI on September 20, 2026 at 14:23 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades. CVE-2026-19641 has been fixed in the following releases: * 4.36.1F and later releases in the 4.36.x train. * 4.35.6M and later releases in the 4.35.x train. * 4.34.8M and later releases in the 4.34.x train. * 4.33.9M and later releases in the 4.33.x train.


Vendor Workaround

The workaround is to disable password based authentication services, such as Telnet and SSH. NOTE: This workaround only works for local authentication. There is no workaround if the device requires password authentication via a remote method, e.g. Terminal Access Controller Access-Control System Plus (TACACS+), Remote Authentication Dial In User Service (RADIUS) or Lightweight Directory Access Protocol (LDAP). Use the following command to disable Telnet. switch(config)#management telnet switch(config-mgmt-telnet)#shutdown   On the client host, use the following command to generate SSH keys. client# ssh-keygen -t ecdsa -b 521 -f testkey   Copy the SSH public key to the device and add it to the local user. switch(config)#copy scp:<local_path_with_keys>/testkey.pub flash: switch(config)#username <user> sshkey file flash:testkey.pub   Add public-key as the first protocol for SSH authentication, keep keyboard-interactive as the second protocol for now. switch(config)#management ssh switch(config)#authentication protocol public-key keyboard-interactive   Once you have verified that the user can know login without a password from the client host, remove keyboard-interactive from SSH authentication protocol configuration. switch(config)#management ssh switch(config)#authentication protocol public-key   WARNING: Incorrect configuration may block logins. Make sure public-key authentication works before removing keyboard-interactive from the configuration. Instead of public key, certificate-based authentication can also be used as a workaround for local users. Please find more details about how to configure certificate-based authentication in the SSH Certificates User Guide https://www.arista.com/en/support/toi/eos-4-22-1f/14286-ssh-certificates .


OpenCVE Recommended Actions

  • Upgrade the EOS firmware to v4.36.1F or a later version in the 4.36.x train, or to v4.35.6M or later in the 4.35.x train, v4.34.8M or later in the 4.34.x train, or v4.33.9M or later in the 4.33.x train.
  • Disable password‑based authentication for Telnet and SSH services if the device does not require password authentication. Use the configuration commands to shut down Telnet and configure SSH to use public‑key or certificate authentication only.
  • If disabling the services is not possible, configure the device to use SSH public‑key authentication and remove keyboard‑interactive or password authentication from the protocol list, and then verify that login functions before removing the fallback. Alternatively, enable certificate‑based authentication with the vendor’s guide.

Generated by OpenCVE AI on September 20, 2026 at 14:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Title On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-15T19:25:06.761Z

Reserved: 2026-08-12T16:48:22.864Z

Link: CVE-2026-19641

cve-icon Vulnrichment

Updated: 2026-09-15T19:25:00.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:17.387

Modified: 2026-09-16T19:08:50.420

Link: CVE-2026-19641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:30:18Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output