CVE-2025-0936

Severity CVSS v4.0:
Pending analysis
Type:
CWE-256 Plaintext Storage of a Password
Publication date:
07/05/2025
Last modified:
08/05/2025

Description

On affected platforms running Arista EOS with a gNMI transport enabled, running the gNOI File TransferToRemote RPC with credentials for a remote server may cause these remote-server credentials to be logged or accounted on the local EOS device or possibly on other remote accounting servers (i.e. TACACS, RADIUS, etc).