CVE-2026-73440: CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer in Arista Networks EOS
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who gains access to this sensitive information could leverage it to perform unauthorized read operations on SNMP tables or to send fraudulent trap notifications to the Network Management System (NMS). This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
AI Analysis
Technical Summary
This vulnerability in Arista EOS involves improper removal of sensitive SNMPv3 user credential information before storage or transfer. Specifically, hashed localized key values for SNMPv3 users may be present in device configurations accessible to authenticated users. Such exposure could allow these users to read SNMP tables without authorization or send fake trap notifications to the Network Management System. The issue affects multiple EOS versions from 1.0.0 up to 4.36.1F as specified. There is no evidence of active exploitation, and the vulnerability was found internally by Arista.
Potential Impact
An authenticated user who accesses the exposed hashed SNMPv3 credentials could perform unauthorized read operations on SNMP tables or send fraudulent trap notifications to the Network Management System. This could lead to unauthorized information disclosure and potential disruption of network monitoring activities. There is no indication of impact on system availability or integrity beyond these actions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor Arista's advisories for updates. Until a fix is available, restrict authenticated user access to device configurations containing SNMP credentials to mitigate risk.
CVE-2026-73440: CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer in Arista Networks EOS
Description
On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remote user credentials may be exposed as a one-way hashed, localized key value within the device's running and sanitized configurations. An authenticated user who gains access to this sensitive information could leverage it to perform unauthorized read operations on SNMP tables or to send fraudulent trap notifications to the Network Management System (NMS). This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.
CVSS v3.1
Score 4.2medium
Affected software
Arista Networks
EOS
pkg:github/arista-networks/eosRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Arista EOS involves improper removal of sensitive SNMPv3 user credential information before storage or transfer. Specifically, hashed localized key values for SNMPv3 users may be present in device configurations accessible to authenticated users. Such exposure could allow these users to read SNMP tables without authorization or send fake trap notifications to the Network Management System. The issue affects multiple EOS versions from 1.0.0 up to 4.36.1F as specified. There is no evidence of active exploitation, and the vulnerability was found internally by Arista.
Potential Impact
An authenticated user who accesses the exposed hashed SNMPv3 credentials could perform unauthorized read operations on SNMP tables or send fraudulent trap notifications to the Network Management System. This could lead to unauthorized information disclosure and potential disruption of network monitoring activities. There is no indication of impact on system availability or integrity beyond these actions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch links or official fixes are provided, users should monitor Arista's advisories for updates. Until a fix is available, restrict authenticated user access to device configurations containing SNMP credentials to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Arista
- Date Reserved
- 2026-08-12T16:39:35.977Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaa692755bf5e2cf553d919
Added to database: 09/16/2026, 10:02:15 UTC
Last enriched: 09/16/2026, 10:16:44 UTC
Last updated: 09/16/2026, 10:32:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.