CVE-2026-73464

8.8

Arista Networks · EOS

A vulnerability in Arista EOS with gNMI enabled allows an authenticated client to execute arbitrary code with root privileges on the switch via a specially crafted request.

Executive summary

A high-severity code injection vulnerability in Arista EOS allows authenticated attackers to achieve root-level remote code execution on affected network switches.

Vulnerability

The vulnerability is a code injection flaw (CWE-94) triggered through the gRPC Network Management Interface (gNMI). An attacker with authenticated access to the gNMI interface can send a crafted request to execute arbitrary code with root privileges.

Business impact

Successful exploitation grants an attacker full administrative control over the affected network switch. This poses a severe risk to network integrity, potentially allowing for traffic interception, persistent backdoors, or complete denial of service. Given the CVSS score of 8.8, this vulnerability represents a significant threat to infrastructure security.

Remediation

Immediate Action: Upgrade to the patched EOS releases: 4.33.9M, 4.34.7.1M, 4.35.6M, 4.36.1F, or any later versions in their respective release trains.

Proactive Monitoring: Monitor network access logs for unusual gRPC traffic patterns and audit all authenticated users with gNMI permissions.

Compensating Controls: Restrict access to the gNMI interface to trusted management IP addresses via ACLs until the firmware update can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the potential for root-level code execution, this vulnerability poses a critical risk to the availability and security of the network core. Administrators must prioritize the application of the vendor-provided security updates to the affected Arista EOS devices to prevent unauthorized administrative control.

More Arista Networks CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources