Impact
A fault in the OpenConfig‑related services on Arista EOS causes requests and responses that contain sensitive data—such as passwords, secret keys, and authentication tokens—to be written to device logs or forwarded to remote accounting servers without scrubbing. The flaw is equivalent to CWE‑256, plain‑text storage of sensitive information, and can expose credentials and other secrets to anyone who can access the logs.
Affected Systems
Arista Networks EOS devices running the 4.36.x train below version 4.36.2F are affected. Any device that has gNMI, gNSI, RESTCONF or NETCONF enabled for configuration or telemetry is susceptible, until a remediated release is installed.
Risk and Exploitability
The CVSS score of 5.1 places the vulnerability at moderate severity and the EPSS score is not available. No publicly documented exploits exist and the issue is not listed in the CISA KEV catalog. However, an attacker who can read device logs or intercept remote accounting traffic can harvest leaked credentials, making the confidentiality risk real for networks that expose these services without additional safeguards. The most likely attack vector is through normal service traffic, so organization should treat this as a potential data disclosure threat.
OpenCVE Enrichment