CVE-2026-2380: Security Advisory 0168
On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.
Examples of sensitive information include: - Sensitive CLI commands (e.g., "username bob secret myPass") - Sensitive OpenConfig YANG leafs (e.g., "system/aaa/global/tacacs/config/secret-key")
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOS 4.36.xto a version that resolves this vulnerability.Fixed in 4.36.2F - Configuration
On affected platforms, ensure that sensitive CLI commands (e.g., those containing credentials like "username bob secret myPass") are not recorded in logs from OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF).
Arista EOS CLI Redaction/avoidance of sensitive CLI commands in logs = Do not log sensitive CLI input such as examples with credentials (e.g., "username bob secret myPass") - Configuration
Prevent sensitive OpenConfig requests/responses from being unintentionally logged for OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF), including sensitive YANG leafs like "system/aaa/global/tacacs/config/secret-key".
Arista EOS OpenConfig services (gNMI/gNSI/RESTCONF/NETCONF) Avoid logging sensitive OpenConfig YANG leafs = Do not log secrets such as "system/aaa/global/tacacs/config/secret-key" - Compensating control
If using OpenConfig-related services (gNMI, gNSI, RESTCONF, NETCONF) on affected platforms, review and restrict access to any logging and remote accounting data stores where sensitive requests/responses may have been recorded.
Event History
Frequently Asked Questions
Which deployments are exposed?
Affected Arista EOS platforms are exposed when OpenConfig-related services such as gNMI, gNSI, RESTCONF, or NETCONF are in use. Sensitive request and response data may be retained locally on the EOS device or by remote accounting servers.
What level of attacker access is indicated by the severity vector?
The provided CVSS vector indicates network reachability, low attack complexity, and low privileges required. No user interaction is required.
Is CloudVision streaming telemetry affected?
No. gRPC-based streaming through the Streaming Telemetry Agent to CloudVision is explicitly identified as not affected.
How can administrators check for potential exposure?
Review local EOS logs and records on remote accounting servers for OpenConfig service requests or responses containing sensitive CLI commands or sensitive OpenConfig YANG leaf values, such as secret keys.