Impact
This vulnerability allows SNMPv3 local or remote user credentials to be exposed as a one-way hashed, localized key value within the device's running configuration. An authenticated user who can read this value could use it to read SNMP tables or send fraudulent trap notifications to the network management system, enabling unauthorized monitoring or manipulation of network device data.
Affected Systems
Arista Networks EOS devices running firmware versions prior to 4.36.2F, 4.35.6M, 4.34.8M, or 4.33.10M are affected. Versions 4.36.2F and later, 4.35.6M and later, 4.34.8M and later, and 4.33.10M and later contain the fix and are immune to this weakness.
Risk and Exploitability
The CVSS score of 2.3 indicates low severity, and the EPSS score of <1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires an attacker with privileged access to read the hashed keys, typically through existing local or remote SNMP credentials. The attack vector is therefore likely restricted to compromised device configuration access rather than a remote code execution.
OpenCVE Enrichment