CVE-2025-0936: Arista Networks Eos
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).
Affected products
- Arista Networks Eos: from 4.33.0, up to and including 4.33.1; from 4.32.0, up to and including 4.32.3M; from 4.31.0, up to and including 4.31.5M; from 4.30.1F, up to and including 4.30.9M
Published 2025-05-07. Last modified 2026-06-17.