CVE-2026-73467: On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.10M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.5M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.2F
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
The CVSS vector indicates that exploitation requires local access, high privileges, high attack complexity, and user interaction. It is not described as remotely exploitable without those conditions.
Which systems are potentially exposed?
Affected Arista EOS platforms with configured TACACS+ servers may be exposed under the unspecified circumstances described in the advisory.
What is the potential security impact if exploitation succeeds?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The affected data is the plaintext shared secrets configured for TACACS+ servers.