CVE-2026-73466: On affected platforms running Arista EOS, under certain circumstances plaintext user passwords
On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.
To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.10M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Exposure is limited to affected Arista EOS platforms where specialized non-standard debugging trace levels have been explicitly enabled. An attacker must already have authenticated local administrative access to the device shell.
Are default deployments affected?
The password logging condition requires specialized non-standard debugging trace levels to be explicitly enabled. The provided information does not indicate that this condition exists in a default configuration.
What can be done if patching is not immediately possible?
Disable the specialized non-standard debugging trace levels that can cause passwords to be written to logs. Restrict authenticated local administrative shell access to trusted administrators.
How can administrators determine whether credentials may have been exposed?
Review whether the specialized non-standard debugging trace levels were enabled during relevant operations, then inspect the associated log files for clear-text user passwords. If such passwords are found, treat them as exposed and rotate them.