GPU VulnDB

Database/Firmware, BMC & network fabric

Arista EOS: gNPSI client credentials can be written in clear text to accounting logs

CVSS 6.0CVE-2026-73457Firmware, BMC & network fabriccurated

Impact

With gRPC Network Packet Sampling Interface enabled, the credentials a gNPSI client uses can be recorded in clear text in local or remote accounting logs. Any authenticated user who can read those logs - and on most fabrics that is a wider group than the people who hold switch credentials, because accounting is shipped to a central syslog or SIEM - recovers a working credential for the switch's telemetry interface. Remote accounting makes the blast radius the log pipeline, not the switch: the credential is now in every index and backup that pipeline feeds.

Who can reach it

An authenticated user with read access to local or remote accounting logs. Exploitation depends on gNPSI being enabled and on conditions Arista does not fully specify (CVSS AT:P).

What to do

Apply the fix per Arista advisory 0158. Independently of the upgrade, rotate the gNPSI client credentials and purge or restrict the accounting logs and downstream log store that already captured them - the leaked credential survives the patch. Disabling gNPSI where it is not used removes the exposure.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.