CVE-2026-73445: Security Advisory 0167
On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect Bootz.
This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer networks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.33.9M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.34.8M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOSto a version that resolves this vulnerability.Fixed in 4.36.1F - Compensating control
If you cannot upgrade immediately, monitor/validate gRPC Network Security Interface (gNSI) Authz Rotate RPC behavior and the Authz policy becoming active from the ongoing RPC stream to ensure no incorrect Authz policy is applied.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that high privileges are required. Exploitation does not require user interaction and can be performed over the network.
Which component is affected, and is Bootz impacted?
The issue affects the gNSI Authz Rotate RPC on affected platforms running Arista EOS. Bootz is explicitly not affected.
What is the impact if exploitation succeeds?
An incorrect Authz policy uploaded during an ongoing Authz Rotate RPC stream may become active. The provided severity vector identifies integrity impact, with no stated confidentiality or availability impact.
Are there known malicious uses in customer networks?
Arista states that it discovered the issue internally and is not aware of malicious use in customer networks.