{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-19641","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:48:22.864Z","datePublished":"2026-09-15T18:17:55.548Z","dateUpdated":"2026-09-15T19:25:06.761Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-15T18:17:55.548Z"},"title":"On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit","datePublic":"2026-09-09T18:15:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-130","descriptions":[{"lang":"en","value":"CAPEC-130 Excessive Allocation"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.0F","versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.5M","versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7.1M","versionType":"custom"},{"status":"affected","version":"0.0.0","lessThanOrEqual":"4.33.8M","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre>On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device.\n\nThis issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.\n</pre>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152"}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-19641, both of the following conditions must be met:\n\n  *  Login authentication must be enabled, which is the default configuration.\nThe following command can be used to verify the login authentication methods.\n \n\n\n\nswitch>show aaa methods authentication \nAuthentication method lists for LOGIN:\n  name=default methods=local\nAuthentication method list for ENABLE:\n  name=default methods=local\nAuthentication method list for DOT1X:\n  name=default methods=\n\n\n \n\n\n\nIf the “methods” under “Authentication method lists for LOGIN” does not show “none”, that means login authentication is enabled.\n\n\n  *  A service that accepts password-based authentication is enabled (e.g., SSH with password authentication, or telnet). By default, SSH with password authentication is enabled and telnet is disabled.\nFor SSH, use the following command to check whether it is enabled for any VRF.\n \n\n\n\nswitch>show management ssh\nUser certificate authentication methods: none (neither trusted CA nor SSL profile configured)\nSSHD status for Default VRF: enabled\nSSH connection limit: 50\nSSH per host connection limit: 20\nFIPS status: disabled\neAPI subsystem: enabled\n\n\n \n\n\n\nUse the following command to check if password-based authentication is enabled for SSH. SSH is vulnerable if “password” or “keyboard-interactive” is listed.\n\n\n\nswitch>show run all section management ssh | grep protocol\n   authentication protocol keyboard-interactive public-key\n\n\n \n\n\n\nFor Telnet, use the following command to check whether it is enabled for any VRF. Telnet is vulnerable if enabled.\n\n\n\nswitch>show management telnet\nTelnet status for Default VRF is enabled \nTelnet session limit is 20\nTelnet session limit per host is 20\n\n\n \n\n\n\nThe device is vulnerable if login authentication is enabled and SSH with password-based method or Telnet is enabled.","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre><p>In order to be vulnerable to CVE-2026-19641, both of the following conditions must be met:</p><ol><li>Login authentication must be enabled, which is the default configuration.<br>The following command can be used to verify the login authentication methods.<br><div>&nbsp;</div><pre>switch&gt;show aaa methods authentication&nbsp;\nAuthentication method lists for LOGIN:\n&nbsp;&nbsp;name=default methods=local\nAuthentication method list for ENABLE:\n&nbsp;&nbsp;name=default methods=local\nAuthentication method list for DOT1X:\n&nbsp;&nbsp;name=default methods=\n</pre><div>&nbsp;</div><p>If the “methods” under “Authentication method lists for LOGIN” does not show “none”, that means login authentication is enabled.</p></li><li>A service that accepts password-based authentication is enabled (e.g., SSH with password authentication, or telnet). By default, SSH with password authentication is enabled and telnet is disabled.<br>For SSH, use the following command to check whether it is enabled for any VRF.<br><div>&nbsp;</div><pre>switch&gt;show management ssh\nUser certificate authentication methods: none (neither trusted CA nor SSL profile configured)\nSSHD status for Default VRF: enabled\nSSH connection limit: 50\nSSH per host connection limit: 20\nFIPS status: disabled\neAPI subsystem: enabled\n</pre><div>&nbsp;</div><p>Use the following command to check if password-based authentication is enabled for SSH. SSH is vulnerable if “password” or “keyboard-interactive” is listed.</p><pre>switch&gt;show run all section management ssh | grep protocol\n&nbsp;&nbsp;&nbsp;authentication protocol keyboard-interactive public-key\n</pre><div>&nbsp;</div><p>For Telnet, use the following command to check whether it is enabled for any VRF. Telnet is vulnerable if enabled.</p><pre>switch&gt;show management telnet\nTelnet status for Default VRF is enabled&nbsp;\nTelnet session limit is 20\nTelnet session limit per host is 20\n</pre><div>&nbsp;</div><p>The device is vulnerable if login authentication is enabled and SSH with password-based method or Telnet is enabled.</p></li></ol></pre>"}]}],"workarounds":[{"lang":"en","value":"The workaround is to disable password based authentication services, such as Telnet and SSH.\n\n\n\nNOTE: This workaround only works for local authentication. There is no workaround if the device requires password authentication via a remote method, e.g. Terminal Access Controller Access-Control System Plus (TACACS+), Remote Authentication Dial In User Service (RADIUS) or Lightweight Directory Access Protocol (LDAP).\n\n\n\nUse the following command to disable Telnet.\n\n\n\nswitch(config)#management telnet\nswitch(config-mgmt-telnet)#shutdown\n\n\n \n\n\n\nOn the client host, use the following command to generate SSH keys.\n\n\n\nclient# ssh-keygen -t ecdsa -b 521 -f testkey\n\n\n \n\n\n\nCopy the SSH public key to the device and add it to the local user.\n\n\n\nswitch(config)#copy scp:<local_path_with_keys>/testkey.pub flash:\nswitch(config)#username <user> sshkey file flash:testkey.pub\n\n\n \n\n\n\nAdd public-key as the first protocol for SSH authentication, keep keyboard-interactive as the second protocol for now.\n\n\n\nswitch(config)#management ssh\nswitch(config)#authentication protocol public-key keyboard-interactive\n\n\n \n\n\n\nOnce you have verified that the user can know login without a password from the client host, remove keyboard-interactive from SSH authentication protocol configuration.\n\n\n\nswitch(config)#management ssh\nswitch(config)#authentication protocol public-key\n\n\n \n\n\n\nWARNING: Incorrect configuration may block logins. Make sure public-key authentication works before removing keyboard-interactive from the configuration.\n\nInstead of public key, certificate-based authentication can also be used as a workaround for local users.\n\n\n\nPlease find more details about how to configure certificate-based authentication in the  SSH Certificates User Guide https://www.arista.com/en/support/toi/eos-4-22-1f/14286-ssh-certificates .","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre><p>The workaround is to disable password based authentication services, such as Telnet and SSH.</p><p>NOTE: This workaround only works for local authentication. There is no workaround if the device requires password authentication via a remote method, e.g. Terminal Access Controller Access-Control System Plus (TACACS+), Remote Authentication Dial In User Service (RADIUS) or Lightweight Directory Access Protocol (LDAP).</p><p>Use the following command to disable Telnet.</p><pre>switch(config)#management telnet\nswitch(config-mgmt-telnet)#shutdown\n</pre><div>&nbsp;</div><p>On the client host, use the following command to generate SSH keys.</p><pre>client# ssh-keygen -t ecdsa -b 521 -f testkey\n</pre><div>&nbsp;</div><p>Copy the SSH public key to the device and add it to the local user.</p><pre>switch(config)#copy scp:&lt;local_path_with_keys&gt;/testkey.pub flash:\nswitch(config)#username &lt;user&gt; sshkey file flash:testkey.pub\n</pre><div>&nbsp;</div><p>Add public-key as the first protocol for SSH authentication, keep keyboard-interactive as the second protocol for now.</p><pre>switch(config)#management ssh\nswitch(config)#authentication protocol public-key keyboard-interactive\n</pre><div>&nbsp;</div><p>Once you have verified that the user can know login without a password from the client host, remove keyboard-interactive from SSH authentication protocol configuration.</p><pre>switch(config)#management ssh\nswitch(config)#authentication protocol public-key\n</pre><div>&nbsp;</div><p>WARNING: Incorrect configuration may block logins. Make sure public-key authentication works before removing keyboard-interactive from the configuration.<br><br>Instead of public key, certificate-based authentication can also be used as a workaround for local users.</p><p>Please find more details about how to configure certificate-based authentication in the <a href=\"https://www.arista.com/en/support/toi/eos-4-22-1f/14286-ssh-certificates\" target=\"_blank\" rel=\"noopener noreferrer\">SSH Certificates User Guide</a>.</p></pre>"}]}],"solutions":[{"lang":"en","value":"The recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.\n\nCVE-2026-19641 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.6M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre>\nThe recommended resolution is to upgrade to a remediated software version at your earliest convenience. Arista recommends customers move to the latest version of each release that contains all the fixes listed below. For more information about upgrading see EOS User Manual: Upgrades and Downgrades.\n\nCVE-2026-19641 has been fixed in the following releases:\n* 4.36.1F and later releases in the 4.36.x train.\n* 4.35.6M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.9M and later releases in the 4.33.x train.\n</pre>"}]}],"source":{"advisory":"Security Advisory 0152","discovery":"INTERNAL","defects":["BUG 1595868","BUG 1966286 (DMF)"]},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-15T19:24:56.712841Z","id":"CVE-2026-19641","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-15T19:25:06.761Z"}}]}}