Exposure of SNMPv3 User Credentials in Arista EOS
CVE-2026-73440
2.3LOW
What is CVE-2026-73440?
A vulnerability in Arista's EOS affects systems configured with SNMP, allowing an authenticated user to access potentially sensitive SNMPv3 local or remote user credentials. These credentials are stored as one-way hashed values in the device's sanitized configurations. If exposed, this information may enable an attacker to conduct unauthorized read operations on SNMP tables or issue fraudulent trap notifications to the Network Management System (NMS). While Arista discovered this issue internally, no known malicious exploitation has been reported in customer networks.
Affected Version(s)
EOS 710 Series 4.36.0F <= 4.36.1F
EOS 710 Series 4.35.0F <= 4.35.5M
EOS 710 Series 4.34.0F <= 4.34.7.1M
