Back

MEDIUM

Under certain circumstances, the gNPSI client credentials might be logged in clear text, in local or remote accounting logs to authenticated users.

Published Sep 16, 2026

Description

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authenticated users.

Affected products

Remediation

Vendor solution

The recommended resolution is to upgrade to a remediated software version at your earliest convenience. CVE-2026-73457 has been fixed in the following releases:

* 4.36.2F and later releases in the 4.36.x train * 4.35.6M and later releases in the 4.35.x train * 4.34.8M and later releases in the 4.34.x train

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Arista
Published Sep 16, 2026
Updated Sep 17, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Sep 17, 2026
NVD
Status Awaiting Analysis
Modified Sep 17, 2026
Red Hat
Severity n/a
Public date n/a