Executive brief
Arista EOS is a network operating system that manages routing and switching on enterprise network devices. When gNSI (gRPC Network Security Interface) Authz is configured with multiple transports, a race condition can cause access control policy updates to fail silently, allowing revoked users to retain unauthorized access to gRPC management interfaces. This could enable unauthorized configuration changes or data access on affected network infrastructure.
Technical details
This vulnerability is a race condition (CWE-362) in the gNSI Authz service when multiple gRPC transports are configured simultaneously. The policy rotation mechanism fails to synchronize properly across transports, causing a new policy to not take effect on all transports. An authenticated user whose permissions were revoked in a policy update may retain access to gRPC interfaces if the policy rotation fails on their transport. The vulnerability requires gNSI Authz to be enabled with multiple transports configured, and affects EOS versions 4.36.0.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.8M and below (4.33.x), 4.32.11M and below (4.32.x), and 4.31.10M and below (4.31.x). Patches are available in 4.36.1F, 4.35.6M, 4.34.7.1M, and 4.33.9M and later.
Affected products
- Arista EOS 4.36.0.1F and below (4.36.x), 4.35.5M and below (4.35.x), 4.34.7M and below (4.34.x), 4.33.8M and below (4.33.x), 4.32.11M and below (4.32.x), 4.31.10M and below (4.31.x)
Timeline
- 2026-09-09: disclosed: Arista Security Advisory 0169 released
- 2026-09-16: advisory: Published to NVD
- 2026-09: patched: Fixes available in 4.36.1F, 4.35.6M, 4.34.7.1M, 4.33.9M and later