{"id":"CVE-2026-73466","title":"On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit th…","summary":"On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit th…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-532"],"vendor":"Arista Networks","product":"EOS","affected":["EOS >= 4.36.0 <= 4.36.1F","EOS >= 4.35.0 <= 4.35.4M","EOS >= 4.34.0 <= 4.34.7M","EOS >= 0.0.0 <= 4.33.9M","EOS <= 4.32.0","EOS <= 4.31.0"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T12:18:26.223","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73466","references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153","label":"psirt@arista.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-16T03:57:02.522424Z"},"epss":0.00094,"epssPercentile":0.00684,"ingestedAt":"2026-09-15T19:42:58.806Z","slug":"CVE-2026-73466","body":"## Overview\n\nOn affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.\n\nTo exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}