ZeroHour

CVE-2026-73447

large

Privileged OS Command Injection in Arista EOS gNSI Certz Service

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-73447 is an OS command injection flaw (CWE-78) in the gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products. An authenticated attacker who already holds high privileges can send a crafted Certz Rotate request, causing arbitrary operating system commands to run with root privileges; the Bootz service is also affected. Successful exploitation grants full control of the device, including its configuration, traffic, and availability. All operators running Arista EOS-based products with the gNSI Certz or Bootz services enabled are in scope. As of this analysis there is no CISA KEV listing, no public proof-of-concept, and no known exploitation.

What to do: Track Arista's PSIRT advisory (CVE assigned by [email protected]) and upgrade EOS to the fixed release it specifies once published. In the interim, restrict access to gNSI/gRPC management services (Certz and Bootz) to trusted management networks via management-plane ACLs, and audit which accounts hold the privileged access required to invoke Certz Rotate. Monitor logs for unexpected or anomalous Certz Rotate and Bootz requests.

Affected
Arista Networks EOS-based products (gNSI Certz service; Bootz service also affected)
Estimated exposure
large≈100k–1M deployed Arista EOS devices potentially in scope (only the subset with gNSI Certz/Bootz enabled and privileged accounts at risk) — Estimated from Arista's large cumulative installed base of EOS switches across data center and campus networks (millions of ports shipped), narrowed by the requirement that gNSI Certz/Bootz be enabled and that the attacker already possess…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.