Impact
The vulnerability allows plaintext user passwords to appear in device log files when specialized, non‑standard debugging trace levels are enabled. If an attacker already has local administrative access to the EOS shell, they can force these trace levels to activate, causing passwords to be written in the logs. The consequence is an information‑disclosure risk, exposing credentials that could be leveraged for further compromise.
Affected Systems
Arista Networks Systems running Arista EOS. Devices on any EOS train prior to the security patch releases that are listed in the CNA solution: 4.36.2F and later in the 4.36.x train, 4.35.5M and later in the 4.35.x train, 4.34.8M and later in the 4.34.x train, and 4.33.10M and later in the 4.33.x train.
Risk and Exploitability
The CVSS base score of 6 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that no active exploits have been observed. Exploitation requires an attacker to already have authenticated local administrative access and to enable the special debug trace. Therefore the risk is limited to environments where privileged users can enable these trace levels, and the potential damage is confined to credential disclosure.
OpenCVE Enrichment