CVE-2026-73465: On affected platforms running Arista EOS, under certain circumstances plaintext private keys

Published Sep 15, 2026
·
Updated

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.

To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Affected Software

1 affected component
Arista Arista EOS

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.33.10M
  2. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.34.8M
  3. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.35.5M
  4. Upgrade

    Upgrade Arista EOS to a version that resolves this vulnerability.

    Fixed in 4.36.2F

Event History

Sep 15, 2026
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires both authenticated local administrative access to the device shell and explicitly enabled specialized, non-standard debugging trace levels. The described condition does not indicate exposure during ordinary operation without those trace levels enabled.

2

What must an attacker be able to do to exploit it?

An attacker must already have authenticated local administrative access to the device shell. They would also need the specialized non-standard debugging trace levels to be explicitly enabled so that plaintext private keys can be written to log files.

3

What should be checked while remediation is pending?

Review whether specialized non-standard debugging trace levels are enabled and inspect relevant log files for plaintext private keys. Restrict local administrative shell access to trusted administrators and disable those trace levels if they are not required.

4

Is there evidence of exploitation in customer environments?

Arista states that it is not aware of malicious exploitation of this vulnerability in customer networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203