{"api_version":"1","generated_at":"2026-09-16T07:45:32+00:00","cve":"CVE-2026-73466","urls":{"html":"https://cve.report/CVE-2026-73466","api":"https://cve.report/api/cve/CVE-2026-73466.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-73466","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-73466"},"summary":{"title":"On affected platforms running Arista EOS, under certain circumstances plaintext user passwords","description":"On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","state":"PUBLISHED","assigner":"Arista","published_at":"2026-09-15 19:17:39","updated_at":"2026-09-16 04:18:40"},"problem_types":["CWE-532","CWE-532 CWE-532 Insertion of Sensitive Information into Log File"],"metrics":[{"version":"4.0","source":"psirt@arista.com","type":"Secondary","score":"6","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6","severity":"MEDIUM","vector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":6,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}},{"version":"3.1","source":"psirt@arista.com","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153","name":"https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153","refsource":"psirt@arista.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73466","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73466","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.36.0 4.36.1F custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.35.0 4.35.4M custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.34.0 4.34.7M custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 0.0.0 4.33.9M custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.32.0 custom","platforms":[]},{"source":"CNA","vendor":"Arista Networks","product":"EOS","version":"affected 4.31.0 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"The workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n\n\nswitch(config)# no trace Aaa enable PyServer levels 4","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-73466","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-15T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-16T03:57:01.245Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"EOS","vendor":"Arista Networks","versions":[{"lessThanOrEqual":"4.36.1F","status":"affected","version":"4.36.0","versionType":"custom"},{"lessThanOrEqual":"4.35.4M","status":"affected","version":"4.35.0","versionType":"custom"},{"lessThanOrEqual":"4.34.7M","status":"affected","version":"4.34.0","versionType":"custom"},{"lessThanOrEqual":"4.33.9M","status":"affected","version":"0.0.0","versionType":"custom"},{"lessThanOrEqual":"4.32.0","status":"affected","version":"0","versionType":"custom"},{"lessThanOrEqual":"4.31.0","status":"affected","version":"0","versionType":"custom"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre><p>In order to be vulnerable to CVE-2026-73466, the following condition must be met:</p><p>PyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword “PyServer”. The level from the output can be 4 or any range that includes 4, e.g. “0-7” or “*”.</p><p>This is an example showing the trace setting “Py*” with level with “0-5”, which will leak the password:</p><pre>switch# show run section trace | grep Aaa\ntrace Aaa setting Py*/0-5</pre></pre>"}],"value":"In order to be vulnerable to CVE-2026-73466, the following condition must be met:\n\n\n\nPyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword “PyServer”. The level from the output can be 4 or any range that includes 4, e.g. “0-7” or “*”.\n\n\n\nThis is an example showing the trace setting “Py*” with level with “0-5”, which will leak the password:\n\n\n\nswitch# show run section trace | grep Aaa\ntrace Aaa setting Py*/0-5"},{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Impact on DANZ Monitoring Fabric (DMF)<p>DANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.</p><p>DMF fabric switches running Switch Light OS are not affected by this vulnerability.</p><p>Customers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.</p><pre>DMF-CONTROLLER&gt; show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; True&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; True&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; False &nbsp; &nbsp; &nbsp; &nbsp; x86_64-ccs-720df-48y-eos</pre>"}],"value":"Impact on DANZ Monitoring Fabric (DMF)\n\nDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\n\n\n\nDMF fabric switches running Switch Light OS are not affected by this vulnerability.\n\n\n\nCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\n\n\n\nDMF-CONTROLLER> show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            True          x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            True          i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            False         x86_64-ccs-720df-48y-eos"}],"datePublic":"2026-09-09T18:37:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.<br><br>To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n</pre>"}],"value":"On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks."}],"impacts":[{"capecId":"CAPEC-37","descriptions":[{"lang":"en","value":"CAPEC-37 Retrieve Embedded Sensitive Data"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":6,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-532","description":"CWE-532 Insertion of Sensitive Information into Log File","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T18:41:04.230Z","orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista"},"references":[{"name":"Arista Security Advisory 0153","tags":["vendor-advisory"],"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre>\nCVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.\n</pre>"}],"value":"CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train."}],"source":{"advisory":"Security Advisory 0153","defects":["BUG 1595866","BUG 1966285 (DMF)"],"discovery":"INTERNAL"},"title":"On affected platforms running Arista EOS, under certain circumstances plaintext user passwords","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<pre><p>The workaround is to disable PyServer level 4 tracing on agent Aaa.</p><pre>switch(config)# no trace Aaa enable PyServer levels 4</pre></pre>"}],"value":"The workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n\n\nswitch(config)# no trace Aaa enable PyServer levels 4"}],"x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","assignerShortName":"Arista","cveId":"CVE-2026-73466","datePublished":"2026-09-15T18:41:04.230Z","dateReserved":"2026-08-12T16:47:18.121Z","dateUpdated":"2026-09-16T03:57:01.245Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-15 19:17:39","lastModifiedDate":"2026-09-16 04:18:40","problem_types":["CWE-532","CWE-532 CWE-532 Insertion of Sensitive Information into Log File"],"metrics":{"cvssMetricV40":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"cvssMetricV31":[{"source":"psirt@arista.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.3,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-15T00:00:00+00:00","id":"CVE-2026-73466","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"73466","Ordinal":"1","Title":"On affected platforms running Arista EOS, under certain circumst","CVE":"CVE-2026-73466","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"73466","Ordinal":"1","NoteData":"On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","Type":"Description","Title":"On affected platforms running Arista EOS, under certain circumst"}]}}}