CVE-2026-2380: Security Advisory 0168

Published Sep 16, 2026
·
Updated

On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.

Examples of sensitive information include: - Sensitive CLI commands (e.g., "username bob secret myPass") - Sensitive OpenConfig YANG leafs (e.g., "system/aaa/global/tacacs/config/secret-key")

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Affected Software

5 affected components
Arista EOS
Arista EOS gNMI
Arista EOS gNSI
Arista EOS RESTCONF
Arista EOS NETCONF

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arista EOS 4.36.x to a version that resolves this vulnerability.

    Fixed in 4.36.2F
  2. Configuration

    On affected platforms, ensure that sensitive CLI commands (e.g., those containing credentials like "username bob secret myPass") are not recorded in logs from OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF).

    Arista EOS CLI Redaction/avoidance of sensitive CLI commands in logs = Do not log sensitive CLI input such as examples with credentials (e.g., "username bob secret myPass")
  3. Configuration

    Prevent sensitive OpenConfig requests/responses from being unintentionally logged for OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF), including sensitive YANG leafs like "system/aaa/global/tacacs/config/secret-key".

    Arista EOS OpenConfig services (gNMI/gNSI/RESTCONF/NETCONF) Avoid logging sensitive OpenConfig YANG leafs = Do not log secrets such as "system/aaa/global/tacacs/config/secret-key"
  4. Compensating control

    If using OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF) on affected platforms, review and restrict access to any logging and remote accounting data stores where sensitive requests/responses may have been recorded.

Event History

Sep 16, 2026
CVE Published
via MITRE·08:48 AM
Data Sourced
via MITRE·08:48 AM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Affected Arista EOS platforms are exposed when OpenConfig-related services such as gNMI, gNSI, RESTCONF, or NETCONF are in use. Sensitive request and response data may be retained locally on the EOS device or by remote accounting servers.

2

What level of attacker access is indicated by the severity vector?

The provided CVSS vector indicates network reachability, low attack complexity, and low privileges required. No user interaction is required.

3

Is CloudVision streaming telemetry affected?

No. gRPC-based streaming through the Streaming Telemetry Agent to CloudVision is explicitly identified as not affected.

4

How can administrators check for potential exposure?

Review local EOS logs and records on remote accounting servers for OpenConfig service requests or responses containing sensitive CLI commands or sensitive OpenConfig YANG leaf values, such as secret keys.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203