CVE-2026-73454: Security Advisory 0165
On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arista EOS gRPC Network Security Interface (gNSI) Credentialzto a version that resolves this vulnerability.Fixed in 4.33.9M - Upgrade
Upgrade
Arista EOS gRPC Network Security Interface (gNSI) Credentialzto a version that resolves this vulnerability.Fixed in 4.34.7.1M - Upgrade
Upgrade
Arista EOS gRPC Network Security Interface (gNSI) Credentialzto a version that resolves this vulnerability.Fixed in 4.35.6M - Upgrade
Upgrade
Arista EOS gRPC Network Security Interface (gNSI) Credentialzto a version that resolves this vulnerability.Fixed in 4.36.1F
Event History
Frequently Asked Questions
What level of attacker access is required to exploit this issue?
The CVSS vector indicates that exploitation is network-based and requires low privileges. No user interaction is required.
What impact is expected if exploitation succeeds?
The vulnerability is rated as having high confidentiality and integrity impact, with no availability impact indicated. A crafted request can modify a target account's properties, potentially granting privileges or access beyond an administrator's intent.