Clear Text Password Exposition in Arista EOS During Non-Standard Debugging
CVE-2026-73466
6MEDIUM
What is CVE-2026-73466?
On systems running Arista EOS, an issue allows user passwords to be recorded in clear text within log files when specific non-standard debugging options are enabled. This poses a risk if the attacker has previously gained local administrative access to the device shell. Notably, the situation arises only under these unique circumstances, and there have been no reports of exploitation in the wild as of yet. The vulnerability was identified by Arista during routine checks.
Affected Version(s)
EOS 4.36.0 <= 4.36.1F
EOS 4.35.0 <= 4.35.4M
EOS 4.34.0 <= 4.34.7M
