CVE-2026-73465: On affected platforms running Arista EOS, under certain circumstances plaintext private keys
On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.
To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.10M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Exposure requires both authenticated local administrative access to the device shell and explicitly enabled specialized, non-standard debugging trace levels. The described condition does not indicate exposure during ordinary operation without those trace levels enabled.
What must an attacker be able to do to exploit it?
An attacker must already have authenticated local administrative access to the device shell. They would also need the specialized non-standard debugging trace levels to be explicitly enabled so that plaintext private keys can be written to log files.
What should be checked while remediation is pending?
Review whether specialized non-standard debugging trace levels are enabled and inspect relevant log files for plaintext private keys. Restrict local administrative shell access to trusted administrators and disable those trace levels if they are not required.
Is there evidence of exploitation in customer environments?
Arista states that it is not aware of malicious exploitation of this vulnerability in customer networks.