CVE-2026-73454

Summary

On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended.

Affected Software

VendorProductVersion RangeStatus
Arista NetworksEOS4.30.0F < 4.31.0Faffected
Arista NetworksEOS4.31.0F < 4.32.0Faffected
Arista NetworksEOS4.32.0F < 4.33.0Faffected
Arista NetworksEOS4.33.0F <= 4.33.8Maffected
Arista NetworksEOS4.34.0F <= 4.34.7Maffected
Arista NetworksEOS4.35.0F <= 4.35.5Maffected
Arista NetworksEOS4.36.0F <= 4.36.0.1Faffected

Weaknesses

  • CWE-77: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

Workarounds

Disable gNSI Credentialz service. Note: Disabling Credentialz prevents gNSI-based credential rotation (SSH keys, passwords, host parameters) but does not affect traditional EOS CLI credential management. Credentialz is not enabled by default.

switch(config)#management api gnsi switch(config-mgmt-api-gnsi)#no service credentialz

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References