Description
On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords in cases where symmetric passwords are required between devices with neighbor protocol relationships.
Scores
CVSS v3
3.8
EPSS
0.0001
EPSS Percentile
2.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-532
Status
published
Products (6)
Arista Networks/EOS
4.29.0 - 4.29.10M
Arista Networks/EOS
4.30.0 - 4.30.10M
Arista Networks/EOS
4.31.0 - 4.31.7M
Arista Networks/EOS
4.32.0 - 4.32.5M
Arista Networks/EOS
4.33.0 - 4.33.3F
Arista Networks/EOS
4.34.0F
Published
Aug 25, 2025
Tracked Since
Feb 18, 2026