Description
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.

To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Published: 2026-09-15
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Plaintext password disclosure via device logs
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows plaintext user passwords to appear in device log files when specialized, non‑standard debugging trace levels are enabled. If an attacker already has local administrative access to the EOS shell, they can force these trace levels to activate, causing passwords to be written in the logs. The consequence is an information‑disclosure risk, exposing credentials that could be leveraged for further compromise.

Affected Systems

Arista Networks Systems running Arista EOS. Devices on any EOS train prior to the security patch releases that are listed in the CNA solution: 4.36.2F and later in the 4.36.x train, 4.35.5M and later in the 4.35.x train, 4.34.8M and later in the 4.34.x train, and 4.33.10M and later in the 4.33.x train.

Risk and Exploitability

The CVSS base score of 6 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that no active exploits have been observed. Exploitation requires an attacker to already have authenticated local administrative access and to enable the special debug trace. Therefore the risk is limited to environments where privileged users can enable these trace levels, and the potential damage is confined to credential disclosure.

Generated by OpenCVE AI on September 15, 2026 at 23:02 UTC.

Remediation

Vendor Solution

CVE-2026-73465 has been fixed in the following releases: * 4.36.2F and later releases in the 4.36.x train. * 4.35.5M and later releases in the 4.35.x train. * 4.34.8M and later releases in the 4.34.x train. * 4.33.10M and later releases in the 4.33.x train.


Vendor Workaround

The workaround is to disable PyServer level 4 tracing on agent Aaa. switch(config)# no trace Aaa enable PyServer levels 4


OpenCVE Recommended Actions

  • Upgrade Arista EOS to the latest release that includes the fix (any release that is 4.36.2F or later in the 4.36.x train, or 4.35.5M or later in the 4.35.x train, or 4.34.8M or later in the 4.34.x train, or 4.33.10M or later in the 4.33.x train).
  • Disable PyServer level 4 tracing on agent Aaa: apply the provided workaround command switch(config)# no trace Aaa enable PyServer levels 4.
  • Audit EOS devices to ensure that non‑standard debugging trace levels are not enabled or permitted for regular users.

Generated by OpenCVE AI on September 15, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Title On affected platforms running Arista EOS, under certain circumstances plaintext user passwords
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arista

Published:

Updated: 2026-09-15T19:27:47.250Z

Reserved: 2026-08-12T16:47:18.121Z

Link: CVE-2026-73466

cve-icon Vulnrichment

Updated: 2026-09-15T19:27:42.731Z

cve-icon NVD

Status : Received

Published: 2026-09-15T19:17:39.337

Modified: 2026-09-15T20:17:44.323

Link: CVE-2026-73466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T23:15:15Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File