Database/Firmware, BMC & network fabric

Arista EOS: gNPSI client credentials can be written in clear text to accounting logs
Impact
With gRPC Network Packet Sampling Interface enabled, the credentials a gNPSI client uses can be recorded in clear text in local or remote accounting logs. Any authenticated user who can read those logs - and on most fabrics that is a wider group than the people who hold switch credentials, because accounting is shipped to a central syslog or SIEM - recovers a working credential for the switch's telemetry interface. Remote accounting makes the blast radius the log pipeline, not the switch: the credential is now in every index and backup that pipeline feeds.
Who can reach it
An authenticated user with read access to local or remote accounting logs. Exploitation depends on gNPSI being enabled and on conditions Arista does not fully specify (CVSS AT:P).
What to do
Apply the fix per Arista advisory 0158. Independently of the upgrade, rotate the gNPSI client credentials and purge or restrict the accounting logs and downstream log store that already captured them - the leaked credential survives the patch. Disabling gNPSI where it is not used removes the exposure.
References
Related entries
- Arista EOS: gNSI authz policy rotation can fail silently, leaving revoked gRPC access in placeCVE-2026-73463 · Arista EOS gNSI Authz service (policy rotation race with multiple gNSI transports)Medium
- Arista EOS: private keys, user passwords and TACACS+ secrets logged in cleartext when debug tracing is onCVE-2026-73465 · Arista EOS logging (secrets written in cleartext under non-standard debug trace levels)Medium
- Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableCVE-2017-15361 · Infineon TPM firmware (RSA key generation)Medium
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.