CVE-2025-3456: On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c
On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords in cases where symmetric passwords are required between devices with neighbor protocol relationships.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3456?
CVE-2025-3456 is classified as a high-severity vulnerability due to the exposure of sensitive encryption keys.
How do I fix CVE-2025-3456?
To remediate CVE-2025-3456, update to the latest version of Arista EOS where the logging of the global common encryption key is addressed.
Which versions of Arista EOS are affected by CVE-2025-3456?
CVE-2025-3456 impacts all versions of Arista EOS that log the global common encryption key in clear text.
What are the risks associated with CVE-2025-3456?
The risks include potential unauthorized access to encrypted secrets if the logged encryption keys are obtained.
Is CVE-2025-3456 being actively exploited?
As of now, there are no public reports confirming active exploitation of CVE-2025-3456.