ZeroHour

CVE-2026-73461

large

Incorrect Privilege Assignment in Arista EOS gRPC OpenConfig AAA Authorization

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

Arista EOS contains a privilege-assignment flaw (CWE-266) in which gRPC requests from an authenticated user to the OpenConfig interface may be evaluated at the wrong privilege level, causing authorization to run against the wrong AAA method list. It is triggered when a user sends a gRPC OpenConfig request to a device on which AAA-based gRPC authorization for OpenConfig is enabled; non-gRPC OpenConfig transports such as NETCONF are not affected. An attacker holding valid credentials could gain authorization for configuration changes or operations beyond their intended privileges, consistent with the 9.4 CVSS 4.0 score's high confidentiality, integrity, and availability impact. Only Arista EOS platforms with this specific gRPC/OpenConfig AAA configuration are affected. No exploitation in the wild, public proof-of-concept, or CISA KEV listing is currently known.

What to do: Inventory EOS devices for OpenConfig over gRPC and check whether AAA-based gRPC authorization is enabled; where present, restrict gRPC access to trusted management hosts via ACLs or management-plane filtering while awaiting the fixed release, since specific fixed EOS versions are not listed in the available data. Review AAA method lists and audit recent gRPC-authenticated sessions for activity performed at unintended privilege levels.

Affected
Arista Networks EOS (Extensible Operating System)
Estimated exposure
large≈10,000–100,000 devices (subset of Arista's large EOS installed base running OpenConfig over gRPC with AAA-based authorization enabled) — Arista EOS is deployed across hundreds of thousands of data center and campus switches, but only the minority of deployments that explicitly enable gRPC-based OpenConfig with AAA-based gRPC authorization are vulnerable, and no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated user to OpenConfig may use the wrong privilege level, resulting in an authorization using the wrong AAA method list. This does not impact non-gRPC OpenConfig requests such as NETCONF.

Weakness
CWE-266
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.