CVE-2026-73453
10.0Arista Networks · EOS
An unauthenticated remote attacker can achieve arbitrary code execution on Arista EOS switches by sending a malicious packet to the P4Runtime interface.
Executive summary
A critical remote code execution vulnerability in Arista EOS allows an unauthenticated attacker to gain full administrative control over affected network switches.
Vulnerability
This vulnerability, classified as improper control of generation of code (CWE-94), exists within the P4Runtime implementation. An unauthenticated attacker can trigger this flaw by sending a specially crafted packet during the initiation of a P4Runtime session.
Business impact
Successful exploitation grants an attacker complete administrative access to the network switch, enabling total system compromise. Given the CVSS score of 10.0, this represents the highest level of severity: it facilitates unauthorized data interception, network disruption, and potential lateral movement deeper into the corporate environment.
Remediation
Immediate Action: Upgrade affected devices to the remediated versions: 4.36.2F, 4.35.6M, 4.34.8M, or later releases in the respective trains. If immediate patching is not feasible, disable the P4Runtime feature if it is not strictly required for network operations.
Proactive Monitoring: Monitor network traffic for anomalous P4Runtime session initiation attempts. Review administrative access logs for unauthorized configuration changes or unexpected command execution.
Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the P4Runtime interface to authorized management IP addresses only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total administrative compromise of network infrastructure, immediate remediation is required. Organizations should prioritize patching devices where P4Runtime is enabled, as this feature serves as the primary vector for exploitation.
More Arista Networks CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Security Advisory 0174 Vendor advisory