Cleartext storage of sensitive information in Arista Extensible Operating System (EOS) - CVE-2026-11704

 

Cleartext storage of sensitive information in Arista Extensible Operating System (EOS) - CVE-2026-11704

Published: June 24, 2026


Vulnerability identifier: #VU135093
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-11704
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to stream unexpected data to CloudVision.

The vulnerability exists due to cleartext storage of sensitive information in the Streaming Telemetry Agent (TerminAttr) when streaming to CloudVision. A remote privileged user can access the stored data to stream unexpected data to CloudVision.

The agent must be configured to stream to CloudVision for exploitation.


Affected software

Arista Extensible Operating System (EOS)

How to mitigate CVE-2026-11704

Install security update from vendor's website.

Arista Extensible Operating System (EOS) - addressed in versions 4.33.9M, 4.34.8M, 4.35.6M, 4.36.1F

External References

Related Security Bulletins