Junglewise Threat Intelligence

CVE-2026-73445: Arista EOS gNSI Authz Rotate RPC policy activation flaw

CVE-2026-73445 · Severity: medium · CVSS 4.9 · Published 2026-09-16

Technologies: Arista Eos. Vendors: Arista.

Executive brief

Arista EOS network switches contain a flaw in the gRPC Network Security Interface (gNSI) authorization policy mechanism that can cause an incorrect authorization policy to become active when using the Authz Rotate RPC. This vulnerability allows a privileged administrator to inadvertently deploy the wrong access control policy, potentially granting or denying network access contrary to the intended configuration and disrupting network security posture.

Technical details

The vulnerability exists in the gNSI Authz Rotate RPC implementation in Arista EOS, where improper input validation (CWE-20) can cause an incorrect authorization policy uploaded during an ongoing RPC stream to become active instead of the finalized policy. The issue is triggered when multiple UploadRequests are sent within a single Rotate RPC without a proper finalizeRotation operation completing. Exploitation requires gNSI Authz to be configured on an OpenConfig gRPC transport and a high-privilege user with API access to the management port (6030). Patches are available in specific EOS versions: 4.36.0.2F and later in 4.36.x, 4.35.6M and later in 4.35.x, 4.34.8M and later in 4.34.x, and 4.33.9M and later in 4.33.x trains.

Affected products

  • Arista EOS 4.36.0.1F and below in 4.36.x; 4.35.5M and below in 4.35.x; 4.34.7M and below in 4.34.x; 4.33.8M and below in 4.33.x; all 4.31.x and 4.32.x releases

Timeline

  • 2026-09-09: disclosed: Initial advisory release
  • 2026-09-22: advisory: CSAF JSON file added to advisory

References

Related threats