{"api_version":"1","generated_at":"2026-09-23T17:26:09+00:00","cve":"CVE-2026-2380","urls":{"html":"https://cve.report/CVE-2026-2380","api":"https://cve.report/api/cve/CVE-2026-2380.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-2380","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-2380"},"summary":{"title":"Security Advisory 0168","description":"On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.\n\nExamples of sensitive information include:\n- Sensitive CLI commands (e.g., \"username bob secret myPass\")\n- Sensitive OpenConfig YANG leafs (e.g., \"system/aaa/global/tacacs/config/secret-key\")\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-09-16 09:17:04","updated_at":"2026-09-16 19:09:28"},"problem_types":["CWE-256","CWE-256 CWE-256 Plaintext Storage of a Password"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"5.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"5.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L","data":{"baseScore":5.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L","version":"4.0"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"7.4","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.4","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","data":{"baseScore":7.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24724-security-advisory-0168","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24724-security-advisory-0168","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-2380","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2380","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.36.0F 4.36.1F custom","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.35.0F 4.36.0F custom","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.34.0F 4.35.0F custom","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.33.0F 4.34.0F custom","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.33.0F custom","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-2380 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n\nNo hotfix is available for this issue.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"The vulnerability can be mitigated by avoiding the transmission of requests containing sensitive information over gNMI, RESTCONF, or NETCONF. Additionally, debug tracing for the OpenConfig or Octa agents should not be enabled, i.e., do not configure \"trace OpenConfig setting */*\" or \"trace Octa setting */*\"; please note that this can only avoid sensitive information showing in the debug traces, but can not mitigate the issue cause by other configurations mentioned in the Required Configuration for Exploitation section.\n\nShould it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent unauthorized credential usage.\n\nUse the following commands to clean up OpenConfig and Octa log files:\n\n  switch(config)# bash sudo truncate -s 0 /var/log/agents/OpenConfig*\n  switch(config)# bash sudo truncate -s 0 /var/log/agents/Octa*\n\nThen use the following commands to clean up previously rotated old log files:\n\n  switch(config)# bash sudo find /var/log/agents -name 'OpenConfig*.gz' -type f -delete\n  switch(config)# bash sudo find /var/log/agents -name 'Octa*.gz' -type f -delete","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"2380","cve":"CVE-2026-2380","epss":"0.002490000","percentile":"0.164240000","score_date":"2026-09-16","updated_at":"2026-09-17 00:07:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-2380","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-16T14:01:30.909167Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-16T14:07:36.480Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["710 Series","720D Series","720XP/722XPM Series","750X Series","7010TX Series","7020R/R4 Series","7130 Series running EOS","7170 Series","7050X3/X4 Series","7060X/X2/X4/X5/X6 Series","7260X/X3 Series","7280R/R2/R3/R4 Series","7300X/X3 Series","7320X Series","7358X4 Series","7368X4 Series","7388X5 Series","7500R/R2/R3 Series","7800R3/R4 Series","7700R4 Series","AWE 5000 Series","AWE 7200R Series","CloudEOS","cEOS-lab","vEOS-lab","CloudVision eXchange, virtual or physical appliance"],"product":"EOS","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"4.36.1F","status":"affected","version":"4.36.0F","versionType":"custom"},{"lessThan":"4.36.0F","status":"affected","version":"4.35.0F","versionType":"custom"},{"lessThan":"4.35.0F","status":"affected","version":"4.34.0F","versionType":"custom"},{"lessThan":"4.34.0F","status":"affected","version":"4.33.0F","versionType":"custom"},{"lessThan":"4.33.0F","status":"affected","version":"0","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>To be vulnerable to CVE-2026-2380, any of the following configurations must be present:</p><ol><li>gNMI server is enabled</li><li>RESTCONF server is enabled</li><li>NETCONF server is enabled</li></ol><p>With any of these servers enabled, the OpenConfig/Octa agent can log sensitive information in the local log file.</p><p>gNMI server enabled:</p><pre>#show running-config section gnmi\nmanagement api gnmi\n   transport grpc default</pre><p>RESTCONF server enabled:</p><pre>#show running-config section restconf\nmanagement api restconf\n   transport https default\n      ssl profile mySslProfile</pre><p>NETCONF server enabled:</p><pre>#show running-config section netconf\nmanagement api netconf\n   transport ssh default</pre><p>In addition to local logging, sensitive information may be recorded on remote accounting servers if any of the following configurations are present:</p><p>gRPC AAA accounting sensitive logging (for gNMI only):</p><pre>#show running-config section gnmi\nmanagement api gnmi\n   transport grpc default\n      accounting requests</pre><p>gNSI.Acctz accounting sensitive logging (for gNMI only):</p><pre>#show running-config section gnmi\nmanagement api gnmi\n   transport grpc default\n#show running-config section gnsi\nmanagement api gnsi\n   service acctz</pre><p>OpenConfig agent tracing sensitive logging (debug tracing enabled at any level):</p><pre>#\ntrace OpenConfig setting */*</pre><p>Octa agent with debug tracing enabled (at any level):</p><pre>#show running-config section trace | grep Octa\ntrace Octa setting */*</pre>"}],"value":"To be vulnerable to CVE-2026-2380, any of the following configurations must be present:\n\n1. gNMI server is enabled\n2. RESTCONF server is enabled\n3. NETCONF server is enabled\n\nWith any of these servers enabled, the OpenConfig/Octa agent can log sensitive information in the local log file.\n\ngNMI server enabled:\n\n  #show running-config section gnmi\n  management api gnmi\n     transport grpc default\n\nRESTCONF server enabled:\n\n  #show running-config section restconf\n  management api restconf\n     transport https default\n        ssl profile mySslProfile\n\nNETCONF server enabled:\n\n  #show running-config section netconf\n  management api netconf\n     transport ssh default\n\nIn addition to local logging, sensitive information may be recorded on remote accounting servers if any of the following configurations are present:\n\ngRPC AAA accounting sensitive logging (for gNMI only):\n\n  #show running-config section gnmi\n  management api gnmi\n     transport grpc default\n        accounting requests\n\ngNSI.Acctz accounting sensitive logging (for gNMI only):\n\n  #show running-config section gnmi\n  management api gnmi\n     transport grpc default\n  #show running-config section gnsi\n  management api gnsi\n     service acctz\n\nOpenConfig agent tracing sensitive logging (debug tracing enabled at any level):\n\n  #\n  trace OpenConfig setting */*\n\nOcta agent with debug tracing enabled (at any level):\n\n  #show running-config section trace | grep Octa\n  trace Octa setting */*"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.</p><p>Examples of sensitive information include:</p><ul><li>Sensitive CLI commands (e.g., &quot;username bob secret myPass&quot;)</li><li>Sensitive OpenConfig YANG leafs (e.g., &quot;system/aaa/global/tacacs/config/secret-key&quot;)</li></ul><p>This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.</p>"}],"value":"On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.\n\nExamples of sensitive information include:\n- Sensitive CLI commands (e.g., \"username bob secret myPass\")\n- Sensitive OpenConfig YANG leafs (e.g., \"system/aaa/global/tacacs/config/secret-key\")\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."}],"metrics":[{"cvssV3_1":{"baseScore":7.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"baseScore":5.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L","version":"4.0"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-256","description":"CWE-256 Plaintext Storage of a Password","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T10:13:36.641Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"name":"Security Advisory 0168","tags":["vendor-advisory"],"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24724-security-advisory-0168"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.</p><p>CVE-2026-2380 has been fixed in the following releases:</p><ul><li>4.36.2F and later releases in the 4.36.x train</li></ul><p>No hotfix is available for this issue.</p>"}],"value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below.\n\nCVE-2026-2380 has been fixed in the following releases:\n- 4.36.2F and later releases in the 4.36.x train\n\nNo hotfix is available for this issue."}],"source":{"advisory":"Security Advisory 0168","defects":["BUG 1207374"],"discovery":"INTERNAL"},"title":"Security Advisory 0168","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The vulnerability can be mitigated by avoiding the transmission of requests containing sensitive information over gNMI, RESTCONF, or NETCONF. Additionally, debug tracing for the OpenConfig or Octa agents should not be enabled, i.e., do not configure &quot;trace OpenConfig setting */*&quot; or &quot;trace Octa setting */*&quot;; please note that this can only avoid sensitive information showing in the debug traces, but can not mitigate the issue cause by other configurations mentioned in the Required Configuration for Exploitation section.</p><p>Should it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent unauthorized credential usage.</p><p>Use the following commands to clean up OpenConfig and Octa log files:</p><pre>switch(config)# bash sudo truncate -s 0 /var/log/agents/OpenConfig*\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/Octa*</pre><p>Then use the following commands to clean up previously rotated old log files:</p><pre>switch(config)# bash sudo find /var/log/agents -name 'OpenConfig*.gz' -type f -delete\nswitch(config)# bash sudo find /var/log/agents -name 'Octa*.gz' -type f -delete</pre>"}],"value":"The vulnerability can be mitigated by avoiding the transmission of requests containing sensitive information over gNMI, RESTCONF, or NETCONF. Additionally, debug tracing for the OpenConfig or Octa agents should not be enabled, i.e., do not configure \"trace OpenConfig setting */*\" or \"trace Octa setting */*\"; please note that this can only avoid sensitive information showing in the debug traces, but can not mitigate the issue cause by other configurations mentioned in the Required Configuration for Exploitation section.\n\nShould it be determined that sensitive information has been logged, the affected log files must be truncated and any compromised secrets rotated to prevent unauthorized credential usage.\n\nUse the following commands to clean up OpenConfig and Octa log files:\n\n  switch(config)# bash sudo truncate -s 0 /var/log/agents/OpenConfig*\n  switch(config)# bash sudo truncate -s 0 /var/log/agents/Octa*\n\nThen use the following commands to clean up previously rotated old log files:\n\n  switch(config)# bash sudo find /var/log/agents -name 'OpenConfig*.gz' -type f -delete\n  switch(config)# bash sudo find /var/log/agents -name 'Octa*.gz' -type f -delete"}]}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-2380","datePublished":"2026-09-16T08:48:53.473Z","dateReserved":"2026-02-11T21:25:18.920Z","dateUpdated":"2026-09-16T14:07:36.480Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 09:17:04","lastModifiedDate":"2026-09-16 19:09:28","problem_types":["CWE-256","CWE-256 CWE-256 Plaintext Storage of a Password"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"LOW","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":3.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-16T14:01:30.909167Z","id":"CVE-2026-2380","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"2380","Ordinal":"1","Title":"Security Advisory 0168","CVE":"CVE-2026-2380","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"2380","Ordinal":"1","NoteData":"On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability.\n\nExamples of sensitive information include:\n- Sensitive CLI commands (e.g., \"username bob secret myPass\")\n- Sensitive OpenConfig YANG leafs (e.g., \"system/aaa/global/tacacs/config/secret-key\")\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","Type":"Description","Title":"Security Advisory 0168"}]}}}