CVE-2026-73447
largePrivileged OS Command Injection in Arista EOS gNSI Certz Service
CVE-2026-73447 is an OS command injection flaw (CWE-78) in the gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products. An authenticated attacker who already holds high privileges can send a crafted Certz Rotate request, causing arbitrary operating system commands to run with root privileges; the Bootz service is also affected. Successful exploitation grants full control of the device, including its configuration, traffic, and availability. All operators running Arista EOS-based products with the gNSI Certz or Bootz services enabled are in scope. As of this analysis there is no CISA KEV listing, no public proof-of-concept, and no known exploitation.
What to do: Track Arista's PSIRT advisory (CVE assigned by [email protected]) and upgrade EOS to the fixed release it specifies once published. In the interim, restrict access to gNSI/gRPC management services (Certz and Bootz) to trusted management networks via management-plane ACLs, and audit which accounts hold the privileged access required to invoke Certz Rotate. Monitor logs for unexpected or anomalous Certz Rotate and Bootz requests.
| Arista Networks EOS-based products (gNSI Certz service; Bootz service also affected) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Interface (gNSI) Certz service on Arista EOS-based products to escalate privileges and execute arbitrary OS commands via a crafted Certz Rotate request. The Bootz service is also affected.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.