Impact
The vulnerability arises when the TACACS+ server shared secrets are logged in plaintext. This occurs only when Tacacs level 6 tracing is enabled on Arista EOS devices—a condition that is not mentioned in the CVE description but is inferred from the workaround instructions and the vendor remediation. Because the raw secrets are written to agent logs, anyone who can read the logs can recover the authentication keys, potentially enabling unauthorized access or privilege escalation. The weakness corresponds to CWE‑532, a failure to protect sensitive information in logs.
Affected Systems
Affected are Arista Networks EOS devices running firmware versions earlier than 4.36.2F in the 4.36 train, earlier than 4.35.5M in the 4.35 train, earlier than 4.34.8M in the 4.34 train, and earlier than 4.33.10M in the 4.33 train. All versions in these trains are vulnerable until the specified patched releases are installed.
Risk and Exploitability
The CVSS score of 6.0 indicates medium severity. EPSS data is not available, so the global exploitation probability is uncertain. The vulnerability is not listed in of active exploitation. The likely attack vector is gaining read access to the device’s agent logs, which can be achieved by local console or SSH access with privileged rights or by exploiting other pathways that expose logs. An attacker who extracts the leaked secrets can authenticate as a TACACS+ client or hijack privileged sessions.
OpenCVE Enrichment