Credential Logging Vulnerability in Arista EOS Affecting gNMI Transport
CVE-2025-0936
6.5MEDIUM
What is CVE-2025-0936?
Arista EOS, when configured with gNMI transport, may expose sensitive remote server credentials during the gNOI File TransferToRemote RPC operation. This exposure can lead to credential logging on the local device or potentially on external accounting servers like TACACS or RADIUS, heightening the risk of unauthorized access to network resources. Security measures should be implemented to safeguard against this vulnerability.
Affected Version(s)
EOS 4.33.0 <= 4.33.1
EOS 4.32.0 <= 4.32.3M
EOS 4.31.0 <= 4.31.5M