Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5511 articles · 220897 vulns · 37/41 feeds (7d)
← Back to list
5.3
CVE-2026-19641
arista · eos

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legit

Description

On affected platforms running Arista EOS with password authentication configured, a specially crafted password can create orphan authentication sessions. Repeated exploitation of this issue can exhaust available authentication resources, resulting in legitimate users being unable to log in to the device. This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.

Affected Products

VendorProductVersions
aristaeos4.36.0, 4.35.0, 4.34.0, 0.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
aristaeoscert_advisory90%

References

  • https://www.arista.com/en/support/advisories-notices/security-advisory/24708-security-advisory-0152

Related News (2 articles)

Tier B
BSI Advisories6d ago
[NEU] [hoch] Arista EOS: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB6d ago
CVE-2026-19641 | Arista EOS up to 4.33.8M/4.34.7.1M/4.35.5M/4.36.0F Authentication resource consumption
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA KEV❌ No
Actively exploited❌ No
CWECWE-116
PublishedSep 15, 2026
Trending Score22
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93952EXPKEV
Security Advisory 0183
Trending: 130
HIGHCVE-2026-73458
On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured, a specially crafted packet can cause the BFD session(s) to go down. This may result in undesirable network changes because various rou
Trending: 24
CRITICALCVE-2026-73456
Under certain circumstances, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.
Trending: 23
CRITICALCVE-2026-73453
Security Advisory 0174
Trending: 22
HIGHCVE-2026-73435
Security Advisory 0171
Trending: 21

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 15, 2026
Discovered by ZDM
Sep 15, 2026