CVE-2025-0936: On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0936?
CVE-2025-0936 is classified as a moderate severity vulnerability affecting Arista EOS.
How do I fix CVE-2025-0936?
To fix CVE-2025-0936, update your Arista EOS to the latest version that addresses this vulnerability.
What are the potential risks associated with CVE-2025-0936?
The risks associated with CVE-2025-0936 include unintentional logging of remote server credentials which could lead to unauthorized access.
Which systems are affected by CVE-2025-0936?
CVE-2025-0936 affects platforms running Arista EOS with gNMI transport enabled.
Can CVE-2025-0936 lead to data exposure?
Yes, CVE-2025-0936 can potentially lead to the exposure of sensitive credentials if not mitigated.