Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-34vr-qc7c-7p38

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 6.3

Описание

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.

To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled.

To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled.

This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

EPSS

Процентиль: 1%
0.00094
Низкий

6 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.3
nvd
4 дня назад

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor must already possess authenticated local administrative access to the device shell, and specialized non-standard debugging trace levels must be explicitly enabled. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

EPSS

Процентиль: 1%
0.00094
Низкий

6 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-532