vulnerability

Arista: EOS: CVE-2025-3456: security-advisory-0122

Severity
2
CVSS
(AV:L/AC:L/Au:S/C:P/I:N/A:N)
Published
Jul 22, 2025
Added
Jul 23, 2025
Modified
Jan 14, 2026

Description

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-config could then be used to obtain protocol specific passwords in cases where symmetric passwords are required between devices with neighbor protocol relationships.

Solution

upgrade-solution-cve-2025-3456
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.