Vulnerabilidad · Publicado 16/09/2026
Plataformas Arista EOS ejecutando servicios OpenConfig (gNMI, gNSI, RESTCONF, NETCONF) registran inadecuadamente solicitudes y respuestas sensibles en el dispositivo local o servidores de contabilidad remota, exponiendo credenciales y configuraciones altas. La vulnerabilidad afecta infraestructuras de redes datacenter y carriers en LATAM que utilizan automatización basada en OpenConfig para gestión de equipos Arista.
On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensitive requests and responses may be unintentionally logged. These may be stored on the local EOS device or recorded on remote accounting servers. Note that gRPC-based streaming via Streaming Telemetry Agent to CloudVision is not affected by this vulnerability. Examples of sensitive information include: - Sensitive CLI commands (e.g., "username bob secret myPass") - Sensitive OpenConfig YANG leafs (e.g., "system/aaa/global/tacacs/config/secret-key") This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
Score: 7.4/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-256
Publicado en NIST NVD.