CVE-2026-73457: Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.
Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
Who can access the exposed credentials?
The credentials may be written to local or remote accounting logs and exposed to authenticated users who can access those logs.
What configuration must be present for exposure to occur?
The affected platform must be running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled. The issue occurs only under certain unspecified circumstances.
Does exploitation require prior access?
Yes. The published vector indicates low privileges are required, and the described exposure is to authenticated users through accounting logs.