Database/Firmware, BMC & network fabric

Arista EOS: private keys, user passwords and TACACS+ secrets logged in cleartext when debug tracing is on
Impact
When specialized non-standard debug trace levels are explicitly enabled, EOS writes secrets to log files in cleartext. Arista split this across three ids for three kinds of secret - CVE-2026-73465 private keys, CVE-2026-73466 user passwords, CVE-2026-73467 TACACS+ shared secrets - one advisory, one score, one fix, so it is recorded here as one issue. The consequence for an operator is credential spill into a place with weaker protection than the credential store: log files, and anything that ships them off-box such as a syslog collector or a support bundle. A leaked TACACS+ shared secret is the worst case, because it is shared across the switch estate and lets an attacker forge or decrypt AAA exchanges, turning one switch's logs into fabric-wide authentication exposure. Arista found this internally and reports no known exploitation.
Who can reach it
Local, authenticated administrative access to the device shell, and the non-standard debug trace levels must have been explicitly enabled. Also reachable indirectly by anyone who can read exported logs or support bundles from an affected switch.
What to do
First, confirm whether the non-standard debug trace levels are enabled anywhere - if not, you are not exposed, and turning them off is the immediate mitigation with no downtime. Then upgrade to the fixed EOS release or hotfix in Arista security advisory 0153, which means a scheduled switch reload. Treat any secret already written to logs as compromised: rotate device keys, user passwords and the TACACS+ shared secret, and purge or restrict the affected logs wherever they were forwarded. Fixed versions are in Arista's advisory only.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Infineon TPM firmware (RSA key generation): RSA keys generated inside affected Infineon TPMs are factorableCVE-2017-15361 · Infineon TPM firmware (RSA key generation)Medium
- STMicroelectronics ST33 TPM (ECDSA timing): Discrete TPM leaks ECDSA nonce data through timing, allowing private keyCVE-2019-16863 · STMicroelectronics ST33 TPM (ECDSA timing)Medium
- Arista EOS (EVPN VXLAN MAC/IP binding): Malformed packets create incorrect MAC-to-IP bindings in an EVPN VXLAN fabricCVE-2020-26569 · Arista EOS (EVPN VXLAN MAC/IP binding)Medium
- Arista EOS (802.1X on access/trunk ports): With 802.1X configured on access or trunk ports and routing enabled on theCVE-2023-5502 · Arista EOS (802.1X on access/trunk ports)Medium
- AMD SEV firmware - RMP protection bypass: An access-control failure in SEV firmware lets a malicious hypervisor bypassCVE-2025-29948 · AMD SEV firmware - RMP protection bypassMedium
- AMD SEV firmware - improper initialization corrupting RMP-covered memory: An initialization defect in SEV firmware letsCVE-2025-29952 · AMD SEV firmware - improper initialization corrupting RMP-covered memoryMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.