Junglewise Threat Intelligence

CVE-2026-73453: Arista EOS P4Runtime arbitrary code execution

CVE-2026-73453 · Severity: critical · CVSS 10 · Published 2026-09-16

Executive brief

Arista EOS network switches support an optional P4Runtime protocol for programmatic packet processing control. An unauthenticated attacker can craft a malicious packet to achieve arbitrary code execution and gain full administrative control over an affected switch, but only if P4Runtime is explicitly enabled (disabled by default). Arista has not observed active exploitation in customer networks.

Technical details

This vulnerability is a code injection flaw (CWE-94) in the P4Runtime session initialization logic. An unauthenticated network-accessible attacker can exploit this by sending a specially crafted packet during P4Runtime session setup to achieve remote code execution with administrative privileges. The vulnerability affects Arista EOS versions through 4.36.1F and earlier in multiple release trains when P4Runtime is configured in non-TLS mode, TLS mode without trusted certificates, or mTLS mode without proper gNSI authorization controls. No user interaction is required; the attack occurs at the protocol level during session negotiation. Patches are available through updated EOS versions beyond the affected release trains.

Affected products

  • Arista EOS 4.36.1F and earlier 4.36.x, 4.35.5M and earlier 4.35.x, 4.34.7M and earlier 4.34.x, all 4.33.x, all 4.32.x, all 4.31.x, all 4.30.x, 4.29.2F and later in 4.29.x

Timeline

  • 2026-09-16: disclosed
  • 2026-09-09: advisory

References

Related threats