Executive brief
Arista EOS is a network operating system that runs on Arista switches and routers used to manage network traffic. An authenticated administrator with high privileges can exploit the gRPC Network Security Interface (gNSI) Certz service to execute arbitrary commands with root privileges, fully compromising the device. This affects multiple EOS versions and platforms used in enterprise networks.
Technical details
The vulnerability is OS command injection (CWE-78) in the gNSI Certz service on Arista EOS-based products. An authenticated user with high privileges can craft a malicious Certz Rotate gRPC request that allows arbitrary OS command execution with root privileges. The Bootz service used for initial provisioning is also affected. The attack requires network access to the gNSI service (default port 6030) and an authenticated session with high privileges (PR:H). Arista has released patches for affected EOS versions and provides mitigations including disabling gNSI Certz or implementing strict authorization policies.
Affected products
- Arista EOS 4.36.0.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.8M and below (4.33.x), all 4.32.x, all 4.31.x, 4.30.2F and later (4.30.x)
Timeline
- 2026-09-09: disclosed: Initial security advisory released by Arista
- 2026-09-16: advisory: CVE-2026-73447 published to NVD