CVE-2026-73456
10.0Arista Networks · EOS
A critical code injection vulnerability in Arista EOS allows an unauthenticated attacker to execute arbitrary code via the gRPC Network Packet Sampling Interface (gNPSI), leading to full system control.
Executive summary
An unauthenticated remote code execution vulnerability in Arista EOS poses a critical risk to network infrastructure by allowing attackers to gain full administrative control over affected switches.
Vulnerability
The vulnerability is a code injection flaw (CWE-94) residing in the gRPC Network Packet Sampling Interface (gNPSI) of Arista EOS. It allows an unauthenticated attacker to send a specially crafted request to the interface, resulting in arbitrary code execution with administrative privileges.
Business impact
The potential for full administrative takeover of core network switches represents a catastrophic business risk. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of network traffic, facilitating data exfiltration, traffic interception, or complete network outages. Given the CVSS score of 10.0, this vulnerability must be treated as a highest priority concern for all organizations utilizing affected Arista hardware.
Remediation
Immediate Action: Upgrade to a remediated software version: 4.36.2F or later for the 4.36.x train, 4.35.6M or later for the 4.35.x train, or 4.34.8M or later for the 4.34.x train.
Proactive Monitoring: Review device logs for anomalous gNPSI activity or unexpected process execution patterns that deviate from established baseline configurations.
Compensating Controls: Disable the gNPSI feature on affected switches if it is not required for production operations, or restrict network access to the gNPSI interface to authorized management subnets via Access Control Lists (ACLs).
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with its automatable nature, necessitates an immediate patching cycle. Administrators should identify all affected Arista EOS devices and schedule maintenance windows to apply the prescribed firmware updates without delay. Until patches are deployed, implementing strict network-level access controls to isolate the gNPSI interface is essential to reduce the attack surface.
More Arista Networks CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by This issue was discovered internally by Arista., per the CVE Program record.