Description
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.
Published: 2026-09-16
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure via Log Exfiltration
Action: Patch ASAP
AI Analysis

Impact

The vulnerability allows the gNPSI client credentials on Arista EOS to be written to local or remote accounting logs in clear text. This can expose authentication secrets to any authenticated user who has access to these log files, effectively leaking credentials that can be reused or misused by an attacker. The flaw is categorized as CWE‑532, which denotes the exposure of sensitive information in logs.

Affected Systems

Arista Networks EOS devices running the 4.34.x, 4.35.x, or 4.36.x train before the specified remediation release. Specifically, versions prior to 4.36.2F in the 4.36 train, 4.35.6M in the 4.35 train, and 4.34.8M in the 4.34 train are impacted.

Risk and Exploitability

The CVSS score of 6 indicates a moderate severity. With an EPSS score below 1% the likelihood of exploitation is currently very low, and the vulnerability is not listed in CISA KEV. However, because the flaw is triggered when gNPSI is enabled and the logs are accessible to authenticated users, the attack vector is likely to be local or remote log inspection. An attacker who can view or retrieve the accounting logs can obtain the credentials directly; no additional privilege escalation is required.

Generated by OpenCVE AI on September 18, 2026 at 01:00 UTC.

Remediation

Vendor Solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73457 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train


Vendor Workaround

To secure the agent against  CVE-2026-73457, the service must be configured to use mutual TLS and only x509-spiffe authentication must be enabled. management security    ssl profile P1       certificate server.crt key server.key       trust certificate ca_client.crt       chain certificate ca_signing.crt ! management api gnpsi    transport grpc t2       ssl profile P1       port 7001       authentication username priority x509-spiffe       no disabled   Logs are disabled by default, including the affected facility EosRpcAuth.To mitigate CVE-2026-73457, ensure the facility EosRpcAuth status is set to disabled. The command below can be used to restore all Gnpsi agent tracing to its default setting. switch(config)# no trace Gnpsi setting   Should it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent gNPSI client credentials leaking. Use the following commands to clean up Gnpsi log files: switch(config)# bash sudo truncate -s 0 /var/log/agents/Gnpsi*   Then use the following commands to clean up previously rotated old log files: switch(config)# bash sudo find /var/log/agents -name 'Gnpsi*.gz' -type f -delete


OpenCVE Recommended Actions

  • Upgrade the EOS firmware to 4.36.2F or later, 4.35.6M or later, or 4.34.8M or later to apply the vendor fix.
  • Configure the gNPSI service to use mutual TLS and enable only x509‑spiffe authentication, as described in the workaround documentation.
  • Disable the EosRpcAuth facility logging by issuing the appropriate command to prevent future credential logs from being recorded.
  • If credential leakage has occurred, truncate existing Gnpsi log files and delete rotated archives, then rotate any compromised credentials immediately.

Generated by OpenCVE AI on September 18, 2026 at 01:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Arista
Arista eos
Vendors & Products Arista
Arista eos

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.
Title Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-17T18:32:20.363Z

Reserved: 2026-08-12T16:45:03.510Z

Link: CVE-2026-73457

cve-icon Vulnrichment

Updated: 2026-09-17T18:32:16.471Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:32.453

Modified: 2026-09-17T19:16:57.187

Link: CVE-2026-73457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:22Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File