{
  "document": {
    "category": "security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "publisher": {
      "category": "vendor",
      "contact_details": "support@arista.com",
      "name": "Arista PSIRT",
      "namespace": "https://www.arista.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Security advisory 153 canonical URL",
        "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/24709-security-advisory-0153"
      }
    ],
    "title": "Security Advisory 153",
    "tracking": {
      "current_release_date": "2026-09-17T11:48:12Z",
      "generator": {
        "engine": {
          "name": "Arista Networks SecEng Service CSAF Generator"
        }
      },
      "id": "Arista Networks Security Advisory 153",
      "initial_release_date": "2026-09-17T11:48:12Z",
      "revision_history": [
        {
          "date": "2026-09-17T11:48:12Z",
          "number": "1",
          "summary": "Document created"
        }
      ],
      "status": "draft",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.5",
                    "product": {
                      "name": "EOS version 4.35.5",
                      "product_id": "CSAFPID-4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.36.2",
                    "product": {
                      "name": "EOS version 4.36.2",
                      "product_id": "CSAFPID-0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 1.0.0",
                    "product": {
                      "name": "EOS version 1.0.0",
                      "product_id": "CSAFPID-6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.34.8",
                    "product": {
                      "name": "EOS version 4.34.8",
                      "product_id": "CSAFPID-1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.15.0",
                    "product": {
                      "name": "EOS version 4.15.0",
                      "product_id": "CSAFPID-3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.35.6",
                    "product": {
                      "name": "EOS version 4.35.6",
                      "product_id": "CSAFPID-7"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "EOS version 4.33.10",
                    "product": {
                      "name": "EOS version 4.33.10",
                      "product_id": "CSAFPID-5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "EOS"
              }
            ],
            "category": "product_family",
            "name": "Software Products"
          }
        ],
        "category": "vendor",
        "name": "Arista Networks, Inc."
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-73465",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1540441"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, under certain circumstances, plaintext private keys may be written to the log files during operations.\n\nTo exploit the vulnerability, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73465\n\nIn order to be vulnerable to CVE-2026-73465, the following condition must be met:\n\nMgmtSecuritySslCertKey trace levels 0, 3 and/or 4, on agent ConfigAgent, must be enabled.\n\nIf MgmtSecuritySslCertKey traces levels 0, 3 and 4 are disabled, there is no exposure to this issue and the message will look something like:\n\n#### CVE-2026-73466\n\nIn order to be vulnerable to CVE-2026-73466, the following condition must be met:\n\nPyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cPyServer\u201d. The level from the output can be 4 or any range that includes 4, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cPy\\*\u201d with level with \u201c0-5\u201d, which will leak the password:\n\n#### CVE-2026-73467\n\nIn order to be vulnerable to CVE-2026-73467, the following condition must be met:\n\nTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cTacacs\u201d. The level from the output can be 6 or any range that includes 6, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cTacacs\\*\u201d with level with \u201c0-7\u201d, which will leak the password:",
          "title": "1540441: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-3"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-4",
          "CSAFPID-5"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73465"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.5",
          "product_ids": [
            "CSAFPID-4"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 4.15.0",
          "product_ids": [
            "CSAFPID-3"
          ]
        },
        {
          "category": "mitigation",
          "details": "The workaround for all three issues involves disabling certain agent tracing levels.\n\nCaution: Disabling these levels will result in the loss of all messages generated at those levels for the given agents.\n\n#### CVE-2026-73465\n\nThe workaround is to disable MgmtSecuritySslCertKey tracing on agent ConfigAgent.\n\n#### CVE-2026-73466\n\nThe workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n#### CVE-2026-73467\n\nThe workaround is to disable Tacacs level 6 tracing on agent Aaa.\n\n#### Clean Up Existing Log Files\n\nIf any of the above agent logging levels have been enabled, it\u2019s necessary to clean up the existing log files to remove the already leaked secrets and keys.\n\nUse the following commands to clean up Aaa or ConfigAgent log files:\n\nThen use the following commands to clean up previously rotated old log files:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-4",
            "CSAFPID-5",
            "CSAFPID-3",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73465"
    },
    {
      "cve": "CVE-2026-73466",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1595866"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, under certain circumstances, user passwords may be written to the log files during operations.\n\nTo exploit the vulnerability, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73465\n\nIn order to be vulnerable to CVE-2026-73465, the following condition must be met:\n\nMgmtSecuritySslCertKey trace levels 0, 3 and/or 4, on agent ConfigAgent, must be enabled.\n\nIf MgmtSecuritySslCertKey traces levels 0, 3 and 4 are disabled, there is no exposure to this issue and the message will look something like:\n\n#### CVE-2026-73466\n\nIn order to be vulnerable to CVE-2026-73466, the following condition must be met:\n\nPyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cPyServer\u201d. The level from the output can be 4 or any range that includes 4, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cPy\\*\u201d with level with \u201c0-5\u201d, which will leak the password:\n\n#### CVE-2026-73467\n\nIn order to be vulnerable to CVE-2026-73467, the following condition must be met:\n\nTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cTacacs\u201d. The level from the output can be 6 or any range that includes 6, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cTacacs\\*\u201d with level with \u201c0-7\u201d, which will leak the password:",
          "title": "1595866: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-6"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-5",
          "CSAFPID-7"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73466"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-7"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "mitigation",
          "details": "The workaround for all three issues involves disabling certain agent tracing levels.\n\nCaution: Disabling these levels will result in the loss of all messages generated at those levels for the given agents.\n\n#### CVE-2026-73465\n\nThe workaround is to disable MgmtSecuritySslCertKey tracing on agent ConfigAgent.\n\n#### CVE-2026-73466\n\nThe workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n#### CVE-2026-73467\n\nThe workaround is to disable Tacacs level 6 tracing on agent Aaa.\n\n#### Clean Up Existing Log Files\n\nIf any of the above agent logging levels have been enabled, it\u2019s necessary to clean up the existing log files to remove the already leaked secrets and keys.\n\nUse the following commands to clean up Aaa or ConfigAgent log files:\n\nThen use the following commands to clean up previously rotated old log files:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-5",
            "CSAFPID-6",
            "CSAFPID-7",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73466"
    },
    {
      "cve": "CVE-2026-73467",
      "id": {
        "system_name": "Arista Bug ID",
        "text": "1595862"
      },
      "notes": [
        {
          "category": "description",
          "text": "On affected platforms running Arista EOS, under certain circumstances, plaintext TACACS+ shared keys may be written to the log files during operations.\n\nTo exploit the vulnerability, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.",
          "title": "CVE Description"
        },
        {
          "category": "other",
          "text": "#### CVE-2026-73465\n\nIn order to be vulnerable to CVE-2026-73465, the following condition must be met:\n\nMgmtSecuritySslCertKey trace levels 0, 3 and/or 4, on agent ConfigAgent, must be enabled.\n\nIf MgmtSecuritySslCertKey traces levels 0, 3 and 4 are disabled, there is no exposure to this issue and the message will look something like:\n\n#### CVE-2026-73466\n\nIn order to be vulnerable to CVE-2026-73466, the following condition must be met:\n\nPyServer trace level 4 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cPyServer\u201d. The level from the output can be 4 or any range that includes 4, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cPy\\*\u201d with level with \u201c0-5\u201d, which will leak the password:\n\n#### CVE-2026-73467\n\nIn order to be vulnerable to CVE-2026-73467, the following condition must be met:\n\nTacacs trace level 6 on agent Aaa must be enabled. The trace setting can be any regex that matches the keyword \u201cTacacs\u201d. The level from the output can be 6 or any range that includes 6, e.g. \u201c0-7\u201d or \u201c\\*\u201d.\n\nThis is an example showing the trace setting \u201cTacacs\\*\u201d with level with \u201c0-7\u201d, which will leak the password:",
          "title": "1595862: Required Config for Exploitation"
        }
      ],
      "product_status": {
        "first_affected": [
          "CSAFPID-6"
        ],
        "fixed": [
          "CSAFPID-0",
          "CSAFPID-1",
          "CSAFPID-5",
          "CSAFPID-7"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "MITRE",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-73467"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.33.10",
          "product_ids": [
            "CSAFPID-5"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.34.8",
          "product_ids": [
            "CSAFPID-1"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.35.6",
          "product_ids": [
            "CSAFPID-7"
          ]
        },
        {
          "category": "vendor_fix",
          "details": "Fixed in EOS version 4.36.2",
          "product_ids": [
            "CSAFPID-0"
          ]
        },
        {
          "category": "none_available",
          "details": "Not fixed in EOS version 1.0.0",
          "product_ids": [
            "CSAFPID-6"
          ]
        },
        {
          "category": "mitigation",
          "details": "The workaround for all three issues involves disabling certain agent tracing levels.\n\nCaution: Disabling these levels will result in the loss of all messages generated at those levels for the given agents.\n\n#### CVE-2026-73465\n\nThe workaround is to disable MgmtSecuritySslCertKey tracing on agent ConfigAgent.\n\n#### CVE-2026-73466\n\nThe workaround is to disable PyServer level 4 tracing on agent Aaa.\n\n#### CVE-2026-73467\n\nThe workaround is to disable Tacacs level 6 tracing on agent Aaa.\n\n#### Clean Up Existing Log Files\n\nIf any of the above agent logging levels have been enabled, it\u2019s necessary to clean up the existing log files to remove the already leaked secrets and keys.\n\nUse the following commands to clean up Aaa or ConfigAgent log files:\n\nThen use the following commands to clean up previously rotated old log files:"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CSAFPID-5",
            "CSAFPID-6",
            "CSAFPID-7",
            "CSAFPID-0",
            "CSAFPID-1"
          ]
        }
      ],
      "title": "CVE-2026-73467"
    }
  ]
}