Impact
The vulnerability allows the gNPSI client credentials on Arista EOS to be written to local or remote accounting logs in clear text. This can expose authentication secrets to any authenticated user who has access to these log files, effectively leaking credentials that can be reused or misused by an attacker. The flaw is categorized as CWE‑532, which denotes the exposure of sensitive information in logs.
Affected Systems
Arista Networks EOS devices running the 4.34.x, 4.35.x, or 4.36.x train before the specified remediation release. Specifically, versions prior to 4.36.2F in the 4.36 train, 4.35.6M in the 4.35 train, and 4.34.8M in the 4.34 train are impacted.
Risk and Exploitability
The CVSS score of 6 indicates a moderate severity. With an EPSS score below 1% the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA KEV. However, because the flaw is triggered when gNPSI is enabled and the logs are accessible to authenticated users, the attack vector is likely to be local or remote log inspection. An attacker who can view or retrieve the accounting logs can obtain the credentials directly; no additional privilege escalation is required.
OpenCVE Enrichment