{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73467","assignerOrgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","state":"PUBLISHED","assignerShortName":"Arista","dateReserved":"2026-08-12T16:47:18.121Z","datePublished":"2026-09-15T18:44:39.048Z","dateUpdated":"2026-09-16T15:51:26.451Z"},"containers":{"cna":{"providerMetadata":{"orgId":"c8b34d1a-69ae-45c3-88fe-f3b3d44f39b7","shortName":"Arista","dateUpdated":"2026-09-15T18:44:39.048Z"},"title":"On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers","datePublic":"2026-09-09T18:37:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-532","description":"CWE-532 Insertion of Sensitive Information into Log File","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-37","descriptions":[{"lang":"en","value":"CAPEC-37 Retrieve Embedded Sensitive Data"}]}],"affected":[{"vendor":"Arista Networks","product":"EOS","versions":[{"status":"affected","version":"4.36.0","lessThanOrEqual":"4.36.1F","versionType":"custom"},{"status":"affected","version":"4.35.0","lessThanOrEqual":"4.35.4M","versionType":"custom"},{"status":"affected","version":"4.34.0","lessThanOrEqual":"4.34.7M","versionType":"custom"},{"status":"affected","version":"0.0.0","lessThanOrEqual":"4.33.9M","versionType":"custom"},{"status":"affected","version":"0","lessThanOrEqual":"4.32.0","versionType":"custom"},{"status":"affected","version":"0","lessThanOrEqual":"4.31.0","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre>On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers\n</pre>"}]}],"references":[{"url":"https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153","name":"Arista Security Advisory 0153","tags":["vendor-advisory"]}],"configurations":[{"lang":"en","value":"In order to be vulnerable to CVE-2026-73467, the following condition must be met:\n\n\n\nTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword “Tacacs”. The level from the output can be 6 or any range that includes 6, e.g. “0-7” or “*”.\n\n\n\nThis is an example showing the trace setting “Tacacs*” with level with “0-7”, which will leak the password:\n\n\n\nswitch# show run section trace | grep Aaa\ntrace Aaa setting Tacacs*/0-7","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre><p>In order to be vulnerable to CVE-2026-73467, the following condition must be met:</p><p>Tacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword “Tacacs”. The level from the output can be 6 or any range that includes 6, e.g. “0-7” or “*”.</p><p>This is an example showing the trace setting “Tacacs*” with level with “0-7”, which will leak the password:</p><pre>switch# show run section trace | grep Aaa\ntrace Aaa setting Tacacs*/0-7</pre></pre>"}]},{"lang":"en","value":"Impact on DANZ Monitoring Fabric (DMF)\n\nDANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.\n\n\n\nDMF fabric switches running Switch Light OS are not affected by this vulnerability.\n\n\n\nCustomers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.\n\n\n\nDMF-CONTROLLER> show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            True          x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            True          i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi                                            False         x86_64-ccs-720df-48y-eos","supportingMedia":[{"type":"text/html","base64":false,"value":"Impact on DANZ Monitoring Fabric (DMF)<p>DANZ Monitoring Fabric (DMF) deploys a fixed version of Arista EOS on certain managed fabric switches. If the EOS version bundled with a DMF release falls within the affected version range of this advisory, DMF deployments using EOS-based switch platforms may be impacted.</p><p>DMF fabric switches running Switch Light OS are not affected by this vulnerability.</p><p>Customers running DMF should run the following command on the controller to identify the EOS version bundled with their deployment.</p><pre>DMF-CONTROLLER&gt; show version details\n...\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Platform files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nFile\nHcl supported Platform\n-------------------------------------------------------------------------------------|-------------|------------------------------|\n...\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; True&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; x86_64-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; True&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; i686-7289-eos\nEOS-4.36.2F-49446791.volgarel.1-x86_64.swi&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; False &nbsp; &nbsp; &nbsp; &nbsp; x86_64-ccs-720df-48y-eos</pre>"}]}],"workarounds":[{"lang":"en","value":"The workaround is to disable Tacacs level 6 tracing on agent Aaa.\n\n\n\nswitch(config)# no trace Aaa enable Tacacs levels 6\n\nClean Up Existing Log Files\n\nIf any of the above agent logging levels have been enabled, it’s necessary to clean up the existing log files to remove the already leaked secrets and keys.\n\n\n\nUse the following commands to clean up Aaa or ConfigAgent log files:\n\n\n\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/Aaa*\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/ConfigAgent*\n\n\n \n\n\n\nThen use the following commands to clean up previously rotated old log files:\n\n\n\nswitch(config)# bash sudo find /var/log/agents -name 'Aaa*.gz' -type f -delete\nswitch(config)# bash sudo find /var/log/agents -name 'ConfigAgent*.gz' -type f -delete","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre><p>The workaround is to disable Tacacs level 6 tracing on agent Aaa.</p><pre>switch(config)# no trace Aaa enable Tacacs levels 6<br><br>Clean Up Existing Log Files<p>If any of the above agent logging levels have been enabled, it’s necessary to clean up the existing log files to remove the already leaked secrets and keys.</p><p>Use the following commands to clean up Aaa or ConfigAgent log files:</p><pre>switch(config)# bash sudo truncate -s 0 /var/log/agents/Aaa*\nswitch(config)# bash sudo truncate -s 0 /var/log/agents/ConfigAgent*\n</pre><div>&nbsp;</div><p>Then use the following commands to clean up previously rotated old log files:</p><pre>switch(config)# bash sudo find /var/log/agents -name 'Aaa*.gz' -type f -delete\nswitch(config)# bash sudo find /var/log/agents -name 'ConfigAgent*.gz' -type f -delete</pre></pre></pre>"}]}],"solutions":[{"lang":"en","value":"CVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.","supportingMedia":[{"type":"text/html","base64":false,"value":"<pre>\nCVE-2026-73465 has been fixed in the following releases:\n* 4.36.2F and later releases in the 4.36.x train.\n* 4.35.5M and later releases in the 4.35.x train.\n* 4.34.8M and later releases in the 4.34.x train.\n* 4.33.10M and later releases in the 4.33.x train.\n</pre>"}]}],"source":{"advisory":"Security Advisory 0153","discovery":"INTERNAL","defects":["BUG 1595862","BUG 1966285 (DMF)"]},"x_generator":{"engine":"Vulnogram 1.0.5"},"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseSeverity":"MEDIUM","baseScore":6.3,"vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H"}},{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6,"vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H"}}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-73467","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-16T03:57:06.873994Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-16T15:51:26.451Z"}}]}}