ZeroHour

CVE-2026-73456

moderate

Unauthenticated Remote Code Execution in Arista EOS via gNPSI

CVSS 4.0
9.2 critical
EPSS
Published
()
Modified
AI analysis

Arista EOS switches running with the gRPC Network Packet Sampling Interface (gNPSI) enabled contain a code-injection flaw (CWE-94) that lets an unauthenticated remote gNPSI client execute arbitrary code by sending a crafted request. Exploitation depends on certain circumstances being met (reflected in the CVSS 4.0 Attack Requirements metric), notably that the gNPSI service is enabled and reachable on the affected platform. A successful attacker gains full administrative control over the compromised switch. Only deployments of Arista EOS with gNPSI enabled are affected; the issue was assigned by Arista's own PSIRT and carries a critical 9.2 CVSS 4.0 score. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported.

What to do: Audit EOS devices for gNPSI; if it is not required, disable it, and where it is required restrict the gRPC endpoint with management ACLs so only trusted hosts can reach it. No fixed EOS version is listed in the source data — monitor the Arista PSIRT advisory for patched releases and upgrade as soon as one is available. Verify that the gNPSI/gRPC listener is not exposed on untrusted or internet-facing networks as an interim mitigation.

Affected
Arista Networks EOS (Extensible Operating System) with gRPC Network Packet Sampling Interface (gNPSI) enabled
Estimated exposure
moderate≈1,000–10,000 switches (estimate; only deployments that have enabled the optional gNPSI feature are exposed) — Arista EOS has a large data-center installed base, but gNPSI is an opt-in packet-sampling/monitoring interface typically restricted to management networks, so only a small fraction of deployments that enable it and lack management ACLs are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control over the compromised switch.

Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.