Executive brief
Arista EOS is network operating system running on enterprise switches. When the gRPC Network Management Interface (gNMI) is enabled, an authenticated attacker can send a specially crafted request to execute arbitrary code with root privileges on the switch, potentially compromising network infrastructure, stealing sensitive data, or causing service outages.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the gNMI implementation of Arista EOS. An authenticated client with gNMI access can exploit this through a specially crafted request over the network to achieve arbitrary code execution with root-level privileges. The attack requires gNMI transport to be explicitly enabled on the affected switch and the attacker to be authenticated to the management interface. No user interaction is required. Affected versions include EOS 4.36.0.1F and earlier in the 4.36.x train, 4.35.5M and earlier in 4.35.x, 4.34.7M and earlier in 4.34.x, 4.33.8M and earlier in 4.33.x, and all releases in 4.32.x, 4.31.x, 4.30.x, and 4.29.x trains. Arista has released patched versions and is not aware of active exploitation in the wild.
Affected products
- Arista EOS 4.36.0.1F and below (4.36.x); 4.35.5M and below (4.35.x); 4.34.7M and below (4.34.x); 4.33.8M and below (4.33.x); all 4.32.x, 4.31.x, 4.30.x, and 4.29.x
Timeline
- 2026-09-09: disclosed
- 2026-09-16: advisory