---
id: CVE-2026-73457
title: >-
  Under certain circumstances on affected platforms running Arista EOS with gRPC
  Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client
  credentials might be logged in clear text in local or remote accounting logs
  to authentica…
summary: >-
  Under certain circumstances on affected platforms running Arista EOS with gRPC
  Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client
  credentials might be logged in clear text in local or remote accounting logs
  to authentica…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-532
vendor: Arista Networks
product: EOS
affected:
  - EOS >= 4.36.0 <= 4.36.1F
  - EOS >= 4.35.0 <= 4.35.5M
  - EOS >= 4.34.2F <= 4.34.7M
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T19:16:57.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73457'
references:
  - url: >-
      https://www.arista.com/en/support/advisories-notices/security-advisory/24714-security-advisory-0158
    label: psirt@arista.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T18:32:07.235252Z'
ingestedAt: '2026-09-16T19:02:30.720Z'
epss: 0.00317
epssPercentile: 0.21917
---

## Overview

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
