Exposure of SNMPv3 User Credentials in Arista EOS
CVE-2026-73440

2.3LOW

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-73440?

A vulnerability in Arista's EOS affects systems configured with SNMP, allowing an authenticated user to access potentially sensitive SNMPv3 local or remote user credentials. These credentials are stored as one-way hashed values in the device's sanitized configurations. If exposed, this information may enable an attacker to conduct unauthorized read operations on SNMP tables or issue fraudulent trap notifications to the Network Management System (NMS). While Arista discovered this issue internally, no known malicious exploitation has been reported in customer networks.

Affected Version(s)

EOS 710 Series 4.36.0F <= 4.36.1F

EOS 710 Series 4.35.0F <= 4.35.5M

EOS 710 Series 4.34.0F <= 4.34.7.1M

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.